PT-2025-41297 · Wonderwhy Er · Desktopcommandermcp

Crem

+1

·

Published

2025-10-08

·

Updated

2025-10-08

·

CVE-2025-11489

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions wonderwhy-er DesktopCommanderMCP versions up to 0.2.13
Description A security issue has been identified in the isPathAllowed function within the src/tools/filesystem.ts file of wonderwhy-er DesktopCommanderMCP. This allows for symlink following, potentially leading to unauthorized access or manipulation of files. The attack requires local access and is considered difficult to exploit. The vendor acknowledges that the restriction features are not intended as hardened security boundaries and recommends using Desktop Commander with Docker for enhanced isolation when security is a primary concern. This vulnerability impacts products that are no longer supported by the maintainer.
Recommendations Versions prior to 0.2.14 are affected. Consider using Desktop Commander with Docker, which provides actual isolation.

Exploit

Fix

Link Following

Weakness Enumeration

Related Identifiers

CVE-2025-11489

Affected Products

Desktopcommandermcp