CVE-2026-10690
wonderwhy-er DesktopCommanderMCP read_file filesystem.ts readFileFromUrl server-side request forgery
CVSS Score
6.3
EPSS Score
0.0%
EPSS Percentile
13th
A vulnerability was identified in wonderwhy-er DesktopCommanderMCP 0.2.37. This affects the function readFileFromUrl of the file src/tools/filesystem.ts of the component read_file. Such manipulation of the argument url leads to server-side request forgery. The attack may be performed from remote. The exploit is publicly available and might be used. The name of the patch is 53699bebba9950047bca16ac4dc8f0568f596aaa. It is best practice to apply a patch to resolve this issue.
| CWE | CWE-918 |
| Vendor | wonderwhy-er |
| Product | desktopcommandermcp |
| Published | Jun 2, 2026 |
| Last Updated | Jun 3, 2026 |
Stay Ahead of the Next One
Get instant alerts for wonderwhy-er desktopcommandermcp
Be the first to know when new medium vulnerabilities affecting wonderwhy-er desktopcommandermcp are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
wonderwhy-er / DesktopCommanderMCP
0.2.37
References
vuldb.com: https://vuldb.com/vuln/367959 vuldb.com: https://vuldb.com/vuln/367959/cti vuldb.com: https://vuldb.com/cve/CVE-2026-10690 vuldb.com: https://vuldb.com/submit/830735 github.com: https://github.com/wonderwhy-er/DesktopCommanderMCP/issues/410 github.com: https://github.com/sorlen008/DesktopCommanderMCP/commit/53699bebba9950047bca16ac4dc8f0568f596aaa github.com: https://github.com/wonderwhy-er/DesktopCommanderMCP/
Credits
๐ skywings (VulDB User)