CVE-2025-11491

⚪ Do wiadomości

Wstrzyknięcie poleceń w DesktopCommanderMCP umożliwia zdalne wykonanie kodu.

CVSS
6.3
EPSS
4.3%
Exploit
poc
Vendor
wonderwhy-er
Opis źródłowy (NVD)

A vulnerability was found in wonderwhy-er DesktopCommanderMCP up to 0.2.13. The impacted element is the function CommandManager of the file src/command-manager.ts. Performing manipulation results in os command injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used.

exploit rce Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS6.3
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)4.3%
Opublikowano (NVD)2025-10-08 19:15:44 UTC
Ostatnia modyfikacja (NVD)2026-10-08 13:10:00 UTC
Referencje