Description
A vulnerability was identified in wonderwhy-er DesktopCommanderMCP 0.2.37. This affects the function readFileFromUrl of the file src/tools/filesystem.ts of the component read_file. Such manipulation of the argument url leads to server-side request forgery. The attack may be performed from remote. The exploit is publicly available and might be used. The name of the patch is 53699bebba9950047bca16ac4dc8f0568f596aaa. It is best practice to apply a patch to resolve this issue.
Published: 2026-06-02
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The DesktopCommanderMCP 0.2.37 component contains a flaw in its readFileFromUrl function that allows an attacker to supply a crafted URL. When the function forwards this URL to an internal HTTP client, the server can be instructed to perform requests to arbitrary destinations. This server‑side request forgery can be triggered from an external network, and publicly available exploits exist. The flaw effectively lets the application initiate outbound requests on behalf of an attacker, potentially affecting confidentiality, integrity, or availability of downstream services.

Affected Systems

The vulnerability impacts wonderwhy‑er DesktopCommanderMCP version 0.2.37. No other product versions are listed as affected in the provided data.

Risk and Exploitability

The CVSS score of 5.3 denotes medium severity. The EPSS score is not available, so the precise likelihood of exploitation remains uncertain. Because the flaw can be invoked remotely by calling the read_file endpoint with a malicious URL, and the application attempts to fetch that URL, the potential impact grows if internal hosts are reachable. The CVE is not listed in CISA’s KEV catalog, yet its public availability and remote trigger suggest that it could be employed by adversaries with minimal effort.

Generated by OpenCVE AI on June 3, 2026 at 04:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the patch identified by commit 53699bebba9950047bca16ac4dc8f0568f596aaa or upgrade to a newer DesktopCommanderMCP release that incorporates the fix
  • If a patch cannot be applied immediately, restrict external users from invoking the read_file endpoint by applying access controls or disabling the feature
  • Enforce network segmentation or firewall rules to limit outbound requests from the application, reducing the potential misuse of the server‑side request capability

Generated by OpenCVE AI on June 3, 2026 at 04:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 03 Jun 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 03 Jun 2026 02:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in wonderwhy-er DesktopCommanderMCP 0.2.37. This affects the function readFileFromUrl of the file src/tools/filesystem.ts of the component read_file. Such manipulation of the argument url leads to server-side request forgery. The attack may be performed from remote. The exploit is publicly available and might be used. The name of the patch is 53699bebba9950047bca16ac4dc8f0568f596aaa. It is best practice to apply a patch to resolve this issue.
Title wonderwhy-er DesktopCommanderMCP read_file filesystem.ts readFileFromUrl server-side request forgery
First Time appeared Wonderwhy-er
Wonderwhy-er desktopcommandermcp
Weaknesses CWE-918
CPEs cpe:2.3:a:wonderwhy-er:desktopcommandermcp:*:*:*:*:*:*:*:*
Vendors & Products Wonderwhy-er
Wonderwhy-er desktopcommandermcp
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Wonderwhy-er Desktopcommandermcp
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-06-03T14:04:32.907Z

Reserved: 2026-06-02T15:40:39.523Z

Link: CVE-2026-10690

cve-icon Vulnrichment

Updated: 2026-06-03T14:03:45.873Z

cve-icon NVD

Status : Received

Published: 2026-06-03T00:16:30.733

Modified: 2026-06-03T16:16:26.630

Link: CVE-2026-10690

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-03T04:15:24Z

Weaknesses