@wonderwhy-er/desktop-commander@0.2.29

MCP server for terminal operations and file editing

  • latest version

    0.2.47

  • latest non vulnerable version

  • first published

    1 years ago

  • latest version published

    28 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the @wonderwhy-er/desktop-commander package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Server-side Request Forgery (SSRF)

    @wonderwhy-er/desktop-commander is a MCP server for terminal operations and file editing

    Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) via the readFileFromUrl function in filesystem.ts when processing the url argument. An attacker can access internal resources or perform unauthorized network requests by supplying crafted URLs.

    How to fix Server-side Request Forgery (SSRF)?

    Upgrade @wonderwhy-er/desktop-commander to version 0.2.38 or higher.

    <0.2.38
    • M
    Regular Expression Denial of Service (ReDoS)

    @wonderwhy-er/desktop-commander is a MCP server for terminal operations and file editing

    Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS) in the start_search process in search-manager.ts when handling the SearchResult[] argument. An attacker can cause excessive resource consumption by submitting specially crafted input that triggers inefficient regular expression processing.

    How to fix Regular Expression Denial of Service (ReDoS)?

    Upgrade @wonderwhy-er/desktop-commander to version 0.2.39 or higher.

    <0.2.39
    • M
    Command Injection

    @wonderwhy-er/desktop-commander is a MCP server for terminal operations and file editing

    Affected versions of this package are vulnerable to Command Injection via the CommandManager class. An attacker can execute arbitrary operating system commands by embedding them command supplied remotely.

    How to fix Command Injection?

    Upgrade @wonderwhy-er/desktop-commander to version 0.2.33 or higher.

    <0.2.33
    • M
    Command Injection

    @wonderwhy-er/desktop-commander is a MCP server for terminal operations and file editing

    Affected versions of this package are vulnerable to Command Injection via the extractBaseCommand function. An attacker can execute arbitrary operating system commands by supplying crafted input that is processed by this function.

    How to fix Command Injection?

    Upgrade @wonderwhy-er/desktop-commander to version 0.2.33 or higher.

    <0.2.33
    • L
    UNIX Symbolic Link (Symlink) Following

    @wonderwhy-er/desktop-commander is a MCP server for terminal operations and file editing

    Affected versions of this package are vulnerable to UNIX Symbolic Link (Symlink) Following via the isPathAllowed function. An attacker can create a symlink inside an allowed directory that points to a restricted location.

    How to fix UNIX Symbolic Link (Symlink) Following?

    Upgrade @wonderwhy-er/desktop-commander to version 0.2.33 or higher.

    <0.2.33