Vulnerabilities/

DesktopCommanderMCP is vulnerable to Uncontrolled Resource Consumption

Severity:
Low

Description

A security flaw has been discovered in wonderwhy-er DesktopCommanderMCP up to 0.2.38. This impacts an unknown function of the file src/search-manager.ts of the component start_search. Performing a manipulation of the argument SearchResult[] results in inefficient regular expression complexity. It is possible to initiate the attack remotely.

Recommendation

Update the @wonderwhy-er/desktop-commander package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@wonderwhy-er/desktop-commander
Anything's wrong? Let us know Last updated on July 10, 2026