CVE-2025-11491
A vulnerability was found in wonderwhy-er DesktopCommanderMCP up to 0.2.13. The impacted element is the function CommandManager of the file src/command-manager.ts. Performing manipulation results in os command injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/wonderwhy-er/DesktopCommanderMCP/issues/217, https://github.com/wonderwhy-er/DesktopCommanderMCP/issues/217#issue-3343853704, https://vuldb.com/?ctiid.327610, https://vuldb.com/?id.327610, https://vuldb.com/?submit.668006
