CNNVD-202510-1135 Information
CNNVD ID
CNNVD-202510-1135
Related CVE
- CNNVD Published: 2025-10-08
Description (Chinese)
Desktop Commander MCP是Eduard Ruzga个人开发者的一个MCP服务器。 Desktop Commander MCP 0.2.13及之前版本存在安全漏洞,该漏洞源于对文件src/tools/filesystem.ts中函数isPathAllowed的操作可能导致符号链接跟随,可能造成本地攻击。
Description (English)
Desktop Commander MCP is an MCP server for Eduardo Ruzga’s personal developer. There is a security loophole in the Desktop Commander MCP 0.2.13 and earlier versions, which stems from the operation of the src/tools/filesystem.ts function IsPathAllowed, which may lead to a symbol link and possibly local attack.
Hazard Level
High
Vulnerability Type
其他
Affected Vendor
个人开发者
Published
2025-10-08
Last Modified
2026-02-24
References
https://github.com/wonderwhy-er/DesktopCommanderMCP/issues/219 https://github.com/wonderwhy-er/DesktopCommanderMCP/issues/219#issue-3343862329 https://github.com/wonderwhy-er/DesktopCommanderMCP/issues/219#issuecomment-3214114903 https://vuldb.com/?ctiid.327606 https://vuldb.com/?id.327606 https://vuldb.com/?submit.668004
Patch
https://github.com/wonderwhy-er/DesktopCommanderMCP/releases
Share on: