Junglewise Threat Intelligence

CVE-2026-10690: wonderwhy-er DesktopCommanderMCP SSRF in readFileFromUrl

CVE-2026-10690 · Severity: medium · CVSS 6.3 · Published 2026-06-03

Vendors: npm.

Executive brief

DesktopCommanderMCP is an MCP server that provides AI assistants (Claude, Gemini, Cursor) with file system and terminal access. A server-side request forgery vulnerability in the read_file tool allows unauthenticated remote requests to internal networks, cloud metadata endpoints, and any host reachable from the server—enabling an attacker to exfiltrate sensitive data by injecting a malicious URL into the AI agent's prompt.

Technical details

A server-side request forgery (SSRF) vulnerability exists in the readFileFromUrl() function in src/tools/filesystem.ts. The vulnerability is triggered when the read_file tool is invoked with isUrl set to true; the user-supplied path parameter is passed directly to Node.js fetch() without validation of destination host, IP range, or protocol. No allowlist, blocklist of private IP ranges (127.x, 10.x, 172.16-31.x, 192.168.x, 169.254.x), or URL scheme restrictions are enforced. An attacker can perform prompt injection into an AI agent integrated with DesktopCommanderMCP, instructing it to invoke read_file with an internal URL (e.g., cloud metadata endpoints or admin interfaces). The agent, unaware of SSRF risks, will comply; the server fetches the URL and returns the full response body to the agent, enabling data exfiltration. A patch addressing URL validation is available at commit 53699bebba9950047bca16ac4dc8f0568f596aaa.

Affected products

  • wonderwhy-er @wonderwhy-er/desktop-commander 0.2.37 and earlier

Timeline

  • 2026-06-03: disclosed: Vulnerability published; exploit publicly available
  • 2026-07-10: advisory: GitHub security advisory GHSA-5xx3-j724-wmx5 published and reviewed
  • 2026: patched: Patch available at commit 53699bebba9950047bca16ac4dc8f0568f596aaa

References

Related threats