Executive brief
DesktopCommanderMCP is an MCP server that provides AI assistants (Claude, Gemini, Cursor) with file system and terminal access. A server-side request forgery vulnerability in the read_file tool allows unauthenticated remote requests to internal networks, cloud metadata endpoints, and any host reachable from the server—enabling an attacker to exfiltrate sensitive data by injecting a malicious URL into the AI agent's prompt.
Technical details
A server-side request forgery (SSRF) vulnerability exists in the readFileFromUrl() function in src/tools/filesystem.ts. The vulnerability is triggered when the read_file tool is invoked with isUrl set to true; the user-supplied path parameter is passed directly to Node.js fetch() without validation of destination host, IP range, or protocol. No allowlist, blocklist of private IP ranges (127.x, 10.x, 172.16-31.x, 192.168.x, 169.254.x), or URL scheme restrictions are enforced. An attacker can perform prompt injection into an AI agent integrated with DesktopCommanderMCP, instructing it to invoke read_file with an internal URL (e.g., cloud metadata endpoints or admin interfaces). The agent, unaware of SSRF risks, will comply; the server fetches the URL and returns the full response body to the agent, enabling data exfiltration. A patch addressing URL validation is available at commit 53699bebba9950047bca16ac4dc8f0568f596aaa.
Affected products
- wonderwhy-er @wonderwhy-er/desktop-commander 0.2.37 and earlier
Timeline
- 2026-06-03: disclosed: Vulnerability published; exploit publicly available
- 2026-07-10: advisory: GitHub security advisory GHSA-5xx3-j724-wmx5 published and reviewed
- 2026: patched: Patch available at commit 53699bebba9950047bca16ac4dc8f0568f596aaa
References
- https://github.com/wonderwhy-er/DesktopCommanderMCP/issues/410
- https://github.com/sorlen008/DesktopCommanderMCP/commit/53699bebba9950047bca16ac4dc8f0568f596aaa
- https://github.com/wonderwhy-er/DesktopCommanderMCP
- https://vuldb.com/cve/CVE-2026-10690
- https://vuldb.com/submit/830735
- https://vuldb.com/vuln/367959