CNNVD-202510-1135 Information

CNNVD ID

CNNVD-202510-1135

CVE-2025-11489

  • CNNVD Published: 2025-10-08

Description (Chinese)

Desktop Commander MCP是Eduard Ruzga个人开发者的一个MCP服务器。 Desktop Commander MCP 0.2.13及之前版本存在安全漏洞,该漏洞源于对文件src/tools/filesystem.ts中函数isPathAllowed的操作可能导致符号链接跟随,可能造成本地攻击。

Description (English)

Desktop Commander MCP is an MCP server for Eduardo Ruzga’s personal developer. There is a security loophole in the Desktop Commander MCP 0.2.13 and earlier versions, which stems from the operation of the src/tools/filesystem.ts function IsPathAllowed, which may lead to a symbol link and possibly local attack.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

个人开发者

Published

2025-10-08

Last Modified

2026-02-24

References

https://github.com/wonderwhy-er/DesktopCommanderMCP/issues/219 https://github.com/wonderwhy-er/DesktopCommanderMCP/issues/219#issue-3343862329 https://github.com/wonderwhy-er/DesktopCommanderMCP/issues/219#issuecomment-3214114903 https://vuldb.com/?ctiid.327606 https://vuldb.com/?id.327606 https://vuldb.com/?submit.668004

Patch

https://github.com/wonderwhy-er/DesktopCommanderMCP/releases

Share on: