Impact
The DesktopCommanderMCP 0.2.37 component contains a flaw in its readFileFromUrl function that allows an attacker to supply a crafted URL. When the function forwards this URL to an internal HTTP client, the server can be instructed to perform requests to arbitrary destinations. This server‑side request forgery can be triggered from an external network, and publicly available exploits exist. The flaw effectively lets the application initiate outbound requests on behalf of an attacker, potentially affecting confidentiality, integrity, or availability of downstream services.
Affected Systems
The vulnerability impacts wonderwhy‑er DesktopCommanderMCP version 0.2.37. No other product versions are listed as affected in the provided data.
Risk and Exploitability
The CVSS score of 5.3 denotes medium severity. The EPSS score is not available, so the precise likelihood of exploitation remains uncertain. Because the flaw can be invoked remotely by calling the read_file endpoint with a malicious URL, and the application attempts to fetch that URL, the potential impact grows if internal hosts are reachable. The CVE is not listed in CISA’s KEV catalog, yet its public availability and remote trigger suggest that it could be employed by adversaries with minimal effort.
OpenCVE Enrichment