@wonderwhy-er/desktop-commander
npm2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting @wonderwhy-er/desktop-commanderpage 1 of 1
- CVE-2026-10690MEDIUMCVSS 6.3EG 6.32026-06-02
A vulnerability was identified in wonderwhy-er DesktopCommanderMCP 0.2.37. This affects the function readFileFromUrl of the file src/tools/filesystem.ts of the component read_file. Such manipulation of the argument url leads to server-side…
- CVE-2026-10691MEDIUMCVSS 4.3EG 4.3✓ Fixed in 0.2.392026-06-02
A security flaw has been discovered in wonderwhy-er DesktopCommanderMCP up to 0.2.38. This impacts an unknown function of the file src/search-manager.ts of the component start_search. Performing a manipulation of the argument SearchResult[…
Check whether @wonderwhy-er/desktop-commander is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for @wonderwhy-er/desktop-commander CVEs against the assets you own.
Start Free Scan →