PT-2025-41297 · Wonderwhy Er · Desktopcommandermcp
Crem
+1
·
Published
2025-10-08
·
Updated
2025-10-08
·
CVE-2025-11489
CVSS v3.1
7.0
High
| Vector | AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
wonderwhy-er DesktopCommanderMCP versions up to 0.2.13
Description
A security issue has been identified in the
isPathAllowed function within the src/tools/filesystem.ts file of wonderwhy-er DesktopCommanderMCP. This allows for symlink following, potentially leading to unauthorized access or manipulation of files. The attack requires local access and is considered difficult to exploit. The vendor acknowledges that the restriction features are not intended as hardened security boundaries and recommends using Desktop Commander with Docker for enhanced isolation when security is a primary concern. This vulnerability impacts products that are no longer supported by the maintainer.Recommendations
Versions prior to 0.2.14 are affected.
Consider using Desktop Commander with Docker, which provides actual isolation.
Exploit
Fix
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Desktopcommandermcp