VYPR

DesktopCommanderMCP

by Sorlen008

CVEs (1)

  • CVE-2026-10690MedJun 3, 2026
    risk 0.34cvss 6.3epss

    A vulnerability was identified in wonderwhy-er DesktopCommanderMCP 0.2.37. This affects the function readFileFromUrl of the file src/tools/filesystem.ts of the component read_file. Such manipulation of the argument url leads to server-side request forgery. The attack may be…