CVE 5.3 MEDIUM

wonderwhy-er DesktopCommanderMCP command-manager.ts CommandManager os command injection_CVE-2025-11491

5.3 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

Description

A vulnerability was found in wonderwhy-er DesktopCommanderMCP up to 0.2.13. The impacted element is the function CommandManager of the file src/command-manager.ts. Performing manipulation results in os command injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used.

Basic Information

ID CVE-2025-11491
Source VulDB
Published Oct 8, 2025 at 19:02
Modified Oct 8, 2025 at 19:31

Affected Product

Vendor wonderwhy-er
Product DesktopCommanderMCP
Version 0.2.0
Affected Versions wonderwhy-er DesktopCommanderMCP 0.2.0
wonderwhy-er DesktopCommanderMCP 0.2.1
wonderwhy-er DesktopCommanderMCP 0.2.2
wonderwhy-er DesktopCommanderMCP 0.2.3
wonderwhy-er DesktopCommanderMCP 0.2.4
wonderwhy-er DesktopCommanderMCP 0.2.5
wonderwhy-er DesktopCommanderMCP 0.2.6
wonderwhy-er DesktopCommanderMCP 0.2.7
wonderwhy-er DesktopCommanderMCP 0.2.8
wonderwhy-er DesktopCommanderMCP 0.2.9
wonderwhy-er DesktopCommanderMCP 0.2.10
wonderwhy-er DesktopCommanderMCP 0.2.11
wonderwhy-er DesktopCommanderMCP 0.2.12
wonderwhy-er DesktopCommanderMCP 0.2.13

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.