PT-2025-41303 · Wonderwhy · Desktopcommandermcp

·

CVE-2025-11491

·

Published

2025-10-08

·

Updated

2025-10-11

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions wonderwhy-er DesktopCommanderMCP versions through 0.2.13
Description A flaw exists in the CommandManager function within the src/command-manager.ts file that allows for operating system command injection. This issue can be triggered remotely. The exploit is publicly available. The CommandManager function is susceptible to manipulation.
Recommendations Versions prior to 0.2.13 should be updated. Consider temporarily disabling the CommandManager function until a patch is available.

Exploit

Fix

OS Command Injection

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-11491

Affected Products

Desktopcommandermcp