CVE-2026-10690
wonderwhy-er DesktopCommanderMCP read_file filesystem.ts readFileFromUrl server-side request forgery
Vexday Risk Score
33Attention
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS 5.3EPSS 0.2%KEV nãoPoC públicaNuclei —Metasploit —Patch referenciado
Lifecycle
02 Jun 2026Published on NVD
Recommendation: Plan a near-term fix — a public PoC already exists.
A vulnerability was identified in wonderwhy-er DesktopCommanderMCP 0.2.37. This affects the function readFileFromUrl of the file src/tools/filesystem.ts of the component read_file. Such manipulation of the argument url leads to server-side request forgery. The attack may be performed from remote. The exploit is publicly available and might be used. The name of the patch is 53699bebba9950047bca16ac4dc8f0568f596aaa. It is best practice to apply a patch to resolve this issue.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Affected products
wonderwhy-er · DesktopCommanderMCPpublic PoCs found — 1
cve_referencegithub.com/wonderwhy-er/DesktopCommanderMCP/issues/410unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
https://github.com/sorlen008/DesktopCommanderMCP/commit/53699bebba9950047bca16ac4dc8f0568f596aaahttps://github.com/wonderwhy-er/DesktopCommanderMCP/https://github.com/wonderwhy-er/DesktopCommanderMCP/issues/410https://vuldb.com/cve/CVE-2026-10690https://vuldb.com/submit/830735https://vuldb.com/vuln/367959https://vuldb.com/vuln/367959/cti