osfeed.dev
Release /

Desktop Commander MCP v0.2.33

Apply folder restrictions to symlink targets when reading or writing existing files.

What changed in v0.2.33

Path validation resolves symlinks, and command blocking handles absolute paths and command substitution.

Install @wonderwhy-er/[email protected] with Node.js 18+ and an MCP-compatible client.

Fixed and improved

Directory validation blocks symlink traversal, and command blocking addresses absolute-path and command-substitution bypasses. These controls remain guardrails rather than a sandbox.

Now worksSet allowed folders, blocked commands, the default shell, file limits and telemetry preferences.
Read the evidence

Seeded by @iluxav with Codex, from the release's public sources. Each change links to its evidence.