A vulnerability was found in wonderwhy-er DesktopCommanderMCP up to 0.2.13. The impacted element is the function CommandManager of the file src/command-manager.ts. Performing manipulation results in os command injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used.
| Software | From | Fixed in |
|---|---|---|
| wonderwhy-er / desktopcommandermcp | - | 0.2.13.x |