CVE-2026-10691

Published: Giu 03, 2026 Last Modified: Giu 03, 2026
ExploitDB:
Other exploit source:
Google Dorks:
LOW 2,1
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
MEDIUM 4,3
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: none
Availability: low
MEDIUM 4,0
Access Vector: network
Access Complexity: low
Authentication: single
Confidentiality: none
Integrity: none
Availability: partial

Description

AI Translation Available

A security flaw has been discovered in wonderwhy-er DesktopCommanderMCP up to 0.2.38. This impacts an unknown function of the file src/search-manager.ts of the component start_search. Performing a manipulation of the argument SearchResult[] results in inefficient regular expression complexity. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 0.2.39 will fix this issue. The patch is named 4ce845f8749b6a159b57b38dcc3357f7222a8078. It is suggested to upgrade the affected component.

400

Uncontrolled Resource Consumption

Draft
Common Consequences
Security Scopes Affected:
Availability Access Control Other
Potential Impacts:
Dos: Crash, Exit, Or Restart Dos: Resource Consumption (Cpu) Dos: Resource Consumption (Memory) Dos: Resource Consumption (Other) Bypass Protection Mechanism Other
Applicable Platforms
Technologies: Not Technology-Specific, AI/ML
View CWE Details
1333

Inefficient Regular Expression Complexity

Draft
Common Consequences
Security Scopes Affected:
Availability
Potential Impacts:
Dos: Resource Consumption (Cpu)
Applicable Platforms
All platforms may be affected
View CWE Details
https://github.com/wonderwhy-er/DesktopCommanderMCP/
https://github.com/wonderwhy-er/DesktopCommanderMCP/commit/4ce845f8749b6a159b57…
https://github.com/wonderwhy-er/DesktopCommanderMCP/issues/375
https://github.com/wonderwhy-er/DesktopCommanderMCP/pull/400
https://github.com/wonderwhy-er/DesktopCommanderMCP/releases/tag/v0.2.39
https://vuldb.com/cve/CVE-2026-10691
https://vuldb.com/submit/830746
https://vuldb.com/vuln/367960
https://vuldb.com/vuln/367960/cti