CVE-2025-11491
critical
CVSS v3
9.8
CVSS v2
6.5
VIR risk
9.8
Description
A vulnerability was found in wonderwhy-er DesktopCommanderMCP up to 0.2.13. The impacted element is the function CommandManager of the file src/command-manager.ts. Performing manipulation results in os command injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used.
Predictions
Exploit likelihood
97%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cna@vuldb.com — https://github.com/wonderwhy-er/DesktopCommanderMCP/issues/217#issue-3343853704
Vendor advisory: cna@vuldb.com — https://github.com/wonderwhy-er/DesktopCommanderMCP/issues/217
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| wonderwhy-er | desktopcommandermcp | {"endIncluding":"0.2.13"} | |
References
CWEs
CWE-77 CWE-78
Verify integrity in audit chain (admin only). AS-IS.