Executive brief
The Anthropic Model Context Protocol (MCP) TypeScript SDK is a library used to build servers that connect AI models to local data and tools. A vulnerability in how the library handles certain web address templates allows an attacker to crash the server or make it unresponsive by sending a specially crafted request. This results in a total service outage for all users connected to the affected AI server.
Technical details
A Regular Expression Denial of Service (ReDoS) vulnerability exists in the UriTemplate class of the @modelcontextprotocol/sdk package. The root cause is located in the partToRegExp() function, which generates regex patterns with nested quantifiers when processing 'exploded' template variables (e.g., {/id*} or {?tags*}). An attacker can exploit this by sending a crafted URI via a 'resources/read' request, triggering catastrophic backtracking. This results in 100% CPU utilization and a complete hang or crash of the MCP server. The issue is fixed in version 1.25.2 by modifying the regex pattern to prevent backtracking.
Affected products
- Anthropic @modelcontextprotocol/sdk >= 1.3.0, < 1.25.2
Timeline
- 2026-01-05: disclosed
- 2026-01-05: advisory
- 2026-01-05: patched: Fixed in version 1.25.2