PT-2026-45884 · Wonderwhy Er · Desktopcommandermcp
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
wonderwhy-er DesktopCommanderMCP version 0.2.37
Description
An issue exists in the
read file component within the readFileFromUrl() function of the src/tools/filesystem.ts file. Remote manipulation of the url argument can lead to server-side request forgery (SSRF), a condition where a server is coerced into making unintended requests to an arbitrary destination.Recommendations
Apply patch 53699bebba9950047bca16ac4dc8f0568f596aaa to version 0.2.37.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Desktopcommandermcp