Description
A vulnerability was identified in wonderwhy-er DesktopCommanderMCP 0.2.37. This affects the function readFileFromUrl of the file src/tools/filesystem.ts of the component read_file. Such manipulation of the argument url leads to server-side request forgery. The attack may be performed from remote. The exploit is publicly available and might be used.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 0.2.37
References
Related Issues
- DesktopCommanderMCP is vulnerable to Uncontrolled Resource Consumption - CVE-2026-10691
- pdfmake is vulnerable to server-side request forgery (SSRF) - CVE-2026-26801
- MagicMirror vulnerable to unauthenticated SSRF via /cors endpoint - CVE-2026-42281
- Angular SSR is vulnerable to SSRF and Header Injection via request handling pipeline - CVE-2026-27739
You might also like:
- Tags:
- npm
- @wonderwhy-er/desktop-commander
Anything's wrong? Let us know Last updated on July 10, 2026


