Medium severity6.3NVD Advisory· Published Jun 3, 2026· Updated Jul 22, 2026
CVE-2026-10690
CVE-2026-10690
Description
A vulnerability was identified in wonderwhy-er DesktopCommanderMCP 0.2.37. This affects the function readFileFromUrl of the file src/tools/filesystem.ts of the component read_file. Such manipulation of the argument url leads to server-side request forgery. The attack may be performed from remote. The exploit is publicly available and might be used. The name of the patch is 53699bebba9950047bca16ac4dc8f0568f596aaa. It is best practice to apply a patch to resolve this issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
@wonderwhy-er/desktop-commandernpm | <= 0.2.37 | — |
Affected products
2- Range: <0.2.37
- Range: <0.2.37
Patches
Vulnerability mechanics
References
8- github.com/advisories/GHSA-5xx3-j724-wmx5ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-10690ghsaADVISORY
- github.com/sorlen008/DesktopCommanderMCP/commit/53699bebba9950047bca16ac4dc8f0568f596aaanvdWEB
- github.com/wonderwhy-er/DesktopCommanderMCP/issues/410nvdWEB
- vuldb.com/cve/CVE-2026-10690nvdWEB
- vuldb.com/submit/830735nvdWEB
- vuldb.com/vuln/367959nvdWEB
- vuldb.com/vuln/367959/ctinvdWEB
News mentions
0No linked articles in our index yet.