PT-2026-45884 · Wonderwhy Er · Desktopcommandermcp

·

CVE-2026-10690

·

Published

2026-06-02

·

Updated

2026-06-03

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions wonderwhy-er DesktopCommanderMCP version 0.2.37
Description An issue exists in the read file component within the readFileFromUrl() function of the src/tools/filesystem.ts file. Remote manipulation of the url argument can lead to server-side request forgery (SSRF), a condition where a server is coerced into making unintended requests to an arbitrary destination.
Recommendations Apply patch 53699bebba9950047bca16ac4dc8f0568f596aaa to version 0.2.37.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-10690
GHSA-5XX3-J724-WMX5

Affected Products

Desktopcommandermcp