Metrics
Affected Vendors & Products
Thu, 09 Oct 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wonderwhy-er
Wonderwhy-er desktopcommandermcp |
|
| Vendors & Products |
Wonderwhy-er
Wonderwhy-er desktopcommandermcp |
Wed, 08 Oct 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 08 Oct 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was found in wonderwhy-er DesktopCommanderMCP up to 0.2.13. The impacted element is the function CommandManager of the file src/command-manager.ts. Performing manipulation results in os command injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used. | |
| Title | wonderwhy-er DesktopCommanderMCP command-manager.ts CommandManager os command injection | |
| Weaknesses | CWE-77 CWE-78 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2025-10-08T19:02:05.860Z
Updated: 2025-10-23T04:25:49.508Z
Reserved: 2025-10-08T10:53:43.606Z
Link: CVE-2025-11491
Updated: 2025-10-08T19:30:41.324Z
Status : Awaiting Analysis
Published: 2025-10-08T19:15:44.137
Modified: 2025-10-08T19:38:09.863
Link: CVE-2025-11491
No data.