Disclosure summary
A vulnerability has been found in wonderwhy-er DesktopCommanderMCP up to 0.2.13. The affected element is the function extractBaseCommand of the file src/command-manager.ts of the component Absolute Path Handler. Such manipulation leads to os command injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The vendor explains: "The usual use case is that AI is asked to do something, picks commands itself, and typically uses simple command names without absolute paths. It's curious why a user would ask the model to bypass restrictions this way. (...) This could potentially be a problem, but we are yet to hear reports of this being an issue in actual workflows. We'll leave this issue open for situations where people may report this as a problem for the long term."
Source-reported weakness categories
CWE-77, CWE-78
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2025-11490
Open original source · Updated Oct 08, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
| Vendor | Product / association | Version / bounds |
|---|---|---|
| wonderwhy-er | desktopcommandermcp | * {"versionEndIncluding":"0.2.13"} |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Exploit, Issue Tracking, Vendor Advisory
- github.com — Exploit, Issue Tracking, Vendor Advisory
- github.com — Issue Tracking
- vuldb.com — Permissions Required, VDB Entry
- vuldb.com — Third Party Advisory, VDB Entry
- vuldb.com — Third Party Advisory, VDB Entry
- github.com — Exploit, Issue Tracking, Vendor Advisory
- github.com — Exploit, Issue Tracking, Vendor Advisory
- github.com — Issue Tracking
PUBLISHED 2025-10-08T15:15:43-04:00
MODIFIED 2026-10-08T09:10:00-04:00
INGESTED 2026-10-08T12:30:36-04:00