Junglewise Threat Intelligence

CVE-2026-0621: Anthropic MCP TypeScript SDK ReDoS in UriTemplate

CVE-2026-0621 · Severity: high · CVSS 7.5 · Published 2026-01-05

Technologies: @modelcontextprotocol/sdk (npm). Vendors: Anthropic, Lfprojects, npm.

Executive brief

The Anthropic Model Context Protocol (MCP) TypeScript SDK is a library used to build servers that connect AI models to local data and tools. A vulnerability in how the library handles certain web address templates allows an attacker to crash the server or make it unresponsive by sending a specially crafted request. This results in a total service outage for all users connected to the affected AI server.

Technical details

A Regular Expression Denial of Service (ReDoS) vulnerability exists in the UriTemplate class of the @modelcontextprotocol/sdk package. The root cause is located in the partToRegExp() function, which generates regex patterns with nested quantifiers when processing 'exploded' template variables (e.g., {/id*} or {?tags*}). An attacker can exploit this by sending a crafted URI via a 'resources/read' request, triggering catastrophic backtracking. This results in 100% CPU utilization and a complete hang or crash of the MCP server. The issue is fixed in version 1.25.2 by modifying the regex pattern to prevent backtracking.

Affected products

  • Anthropic @modelcontextprotocol/sdk >= 1.3.0, < 1.25.2

Timeline

  • 2026-01-05: disclosed
  • 2026-01-05: advisory
  • 2026-01-05: patched: Fixed in version 1.25.2

References

Related threats