CVE-2026-10691
- EPSS 0.35%
- Veröffentlicht 02.06.2026 23:30:14
- Zuletzt bearbeitet 04.06.2026 16:35:27
A security flaw has been discovered in wonderwhy-er DesktopCommanderMCP up to 0.2.38. This impacts an unknown function of the file src/search-manager.ts of the component start_search. Performing a manipulation of the argument SearchResult[] results i...
CVE-2026-10690
- EPSS 0.21%
- Veröffentlicht 02.06.2026 23:15:08
- Zuletzt bearbeitet 04.06.2026 16:37:27
A vulnerability was identified in wonderwhy-er DesktopCommanderMCP 0.2.37. This affects the function readFileFromUrl of the file src/tools/filesystem.ts of the component read_file. Such manipulation of the argument url leads to server-side request fo...
CVE-2025-11491
- EPSS 4.35%
- Veröffentlicht 08.10.2025 19:02:05
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability was found in wonderwhy-er DesktopCommanderMCP up to 0.2.13. The impacted element is the function CommandManager of the file src/command-manager.ts. Performing manipulation results in os command injection. It is possible to initiate th...
CVE-2025-11490
- EPSS 3.59%
- Veröffentlicht 08.10.2025 18:32:05
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability has been found in wonderwhy-er DesktopCommanderMCP up to 0.2.13. The affected element is the function extractBaseCommand of the file src/command-manager.ts of the component Absolute Path Handler. Such manipulation leads to os command ...
- EPSS 0.22%
- Veröffentlicht 08.10.2025 18:15:34
- Zuletzt bearbeitet 29.04.2026 01:00:01
A security vulnerability has been detected in wonderwhy-er DesktopCommanderMCP up to 0.2.13. This vulnerability affects the function isPathAllowed of the file src/tools/filesystem.ts. The manipulation leads to symlink following. The attack can only b...