GHSA-5xx3-j724-wmx5

Suggest an improvement
Source
https://github.com/advisories/GHSA-5xx3-j724-wmx5
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-5xx3-j724-wmx5/GHSA-5xx3-j724-wmx5.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-5xx3-j724-wmx5
Aliases
Published
2026-06-03T00:30:27Z
Modified
2026-07-10T17:41:40Z
Severity
  • 6.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L CVSS Calculator
  • 2.1 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
DesktopCommanderMCP is vulnerable to SSRF
Details

A vulnerability was identified in wonderwhy-er DesktopCommanderMCP 0.2.37. This affects the function readFileFromUrl of the file src/tools/filesystem.ts of the component read_file. Such manipulation of the argument url leads to server-side request forgery. The attack may be performed from remote. The exploit is publicly available and might be used. The name of the patch is 53699bebba9950047bca16ac4dc8f0568f596aaa. It is best practice to apply a patch to resolve this issue.

Database specific
{
    "cwe_ids":  [
        "CWE-918"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-07-10T17:15:09Z",
    "nvd_published_at":  "2026-06-03T00:16:30Z",
    "severity":  "LOW"
}
References

Affected packages

npm / @wonderwhy-er/desktop-commander

Package

Name
@wonderwhy-er/desktop-commander
View open source insights on deps.dev
Purl
pkg:npm/%40wonderwhy-er/desktop-commander

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
0.2.37

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-5xx3-j724-wmx5/GHSA-5xx3-j724-wmx5.json"