Vulnerabilities/

DesktopCommanderMCP is vulnerable to SSRF

Severity:
Low

Description

A vulnerability was identified in wonderwhy-er DesktopCommanderMCP 0.2.37. This affects the function readFileFromUrl of the file src/tools/filesystem.ts of the component read_file. Such manipulation of the argument url leads to server-side request forgery. The attack may be performed from remote. The exploit is publicly available and might be used.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
@wonderwhy-er/desktop-commander
Anything's wrong? Let us know Last updated on July 10, 2026