Description
A security flaw has been discovered in wonderwhy-er DesktopCommanderMCP up to 0.2.38. This impacts an unknown function of the file src/search-manager.ts of the component start_search. Performing a manipulation of the argument SearchResult[] results in inefficient regular expression complexity. It is possible to initiate the attack remotely.
Recommendation
Update the @wonderwhy-er/desktop-commander package to the latest compatible version. Followings are version details:
- Affected version(s): < 0.2.39
- Patched version(s): 0.2.39
References
Related Issues
- DesktopCommanderMCP is vulnerable to SSRF - CVE-2026-10690
- @ai-sdk/provider-utils has an Uncontrolled Resource Consumption issue - CVE-2026-8769
- Cattown is Vulnerable to Uncontrolled Resource Consumption through Inefficient Regular Expression Complexity - CVE-2025-58451
- @isaacs/brace-expansion has Uncontrolled Resource Consumption - CVE-2026-25547
You might also like:
- Tags:
- npm
- @wonderwhy-er/desktop-commander
Anything's wrong? Let us know Last updated on July 10, 2026


