@wonderwhy-er/desktop-commander

MCP server for terminal operations and file editing
Licenses: MIT

Direct Vulnerabilities

Known vulnerabilities in the @wonderwhy-er/desktop-commander package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • M
Command Injection

<0.2.33
  • M
Command Injection

<0.2.33
  • L
UNIX Symbolic Link (Symlink) Following

<0.2.33

Package versions

111 VERSIONS IN TOTAL See all versions
versionpublisheddirect vulnerabilities
0.2.4114 May, 2026
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
0.2.4027 Apr, 2026
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
0.2.3923 Apr, 2026
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
0.2.383 Mar, 2026
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
0.2.3720 Feb, 2026
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
0.2.3616 Feb, 2026
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
0.2.359 Feb, 2026
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
0.2.342 Feb, 2026
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
0.2.331 Feb, 2026
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
0.2.3223 Jan, 2026
  • 0
    C
  • 0
    H
  • 2
    M
  • 1
    L