wonderwhy-er has 3 CVEs on record. The median CVSS is 6.3 (medium).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.3
- Publish → KEV
- —
- Last 90 days
- 0 prev 0
Worst active — by depth score
CVE-2025-11491Medium· 6.3A vulnerability was found in wonderwhy-er DesktopCommanderMCP up to 0.2.1336CVE-2025-11490Medium· 6.3A vulnerability has been found in wonderwhy-er DesktopCommanderMCP up to 0.2.1335CVE-2025-11489Medium· 4.5A security vulnerability has been detected in wonderwhy-er DesktopCommanderMCP up to 0.2.1325
wonderwhy-er vulnerabilities
CVEs affecting wonderwhy-er, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2025-11491Medium· 6.3A vulnerability was found in wonderwhy-er DesktopCommanderMCP up to 0.2.13
A vulnerability was found in wonderwhy-er DesktopCommanderMCP up to 0.2.13. The impacted element is the function CommandManager of the file src/command-manager.ts. Performing manipulation results in os command injection. It is possible t…
CVE-2025-11490Medium· 6.3A vulnerability has been found in wonderwhy-er DesktopCommanderMCP up to 0.2.13
A vulnerability has been found in wonderwhy-er DesktopCommanderMCP up to 0.2.13. The affected element is the function extractBaseCommand of the file src/command-manager.ts of the component Absolute Path Handler. Such manipulation leads t…
CVE-2025-11489Medium· 4.5A security vulnerability has been detected in wonderwhy-er DesktopCommanderMCP up to 0.2.13
A security vulnerability has been detected in wonderwhy-er DesktopCommanderMCP up to 0.2.13. This vulnerability affects the function isPathAllowed of the file src/tools/filesystem.ts. The manipulation leads to symlink following. The atta…