@wonderwhy-er/desktop-commander@0.2.32

MCP server for terminal operations and file editing

  • latest version

    0.2.41

  • latest non vulnerable version

  • first published

    1 years ago

  • latest version published

    7 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the @wonderwhy-er/desktop-commander package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Command Injection

    @wonderwhy-er/desktop-commander is a MCP server for terminal operations and file editing

    Affected versions of this package are vulnerable to Command Injection via the CommandManager class. An attacker can execute arbitrary operating system commands by embedding them command supplied remotely.

    How to fix Command Injection?

    Upgrade @wonderwhy-er/desktop-commander to version 0.2.33 or higher.

    <0.2.33
    • M
    Command Injection

    @wonderwhy-er/desktop-commander is a MCP server for terminal operations and file editing

    Affected versions of this package are vulnerable to Command Injection via the extractBaseCommand function. An attacker can execute arbitrary operating system commands by supplying crafted input that is processed by this function.

    How to fix Command Injection?

    Upgrade @wonderwhy-er/desktop-commander to version 0.2.33 or higher.

    <0.2.33
    • L
    UNIX Symbolic Link (Symlink) Following

    @wonderwhy-er/desktop-commander is a MCP server for terminal operations and file editing

    Affected versions of this package are vulnerable to UNIX Symbolic Link (Symlink) Following via the isPathAllowed function. An attacker can create a symlink inside an allowed directory that points to a restricted location.

    How to fix UNIX Symbolic Link (Symlink) Following?

    Upgrade @wonderwhy-er/desktop-commander to version 0.2.33 or higher.

    <0.2.33