Executive brief
Code Index MCP, a tool used to index and search through source code, is vulnerable to a denial-of-service attack. An attacker can provide a specially crafted search pattern that causes the system's search engine to consume excessive CPU resources. This can lead to the service becoming unresponsive, effectively preventing legitimate users from searching their codebase.
Technical details
A Regular Expression Denial of Service (ReDoS) vulnerability exists in the `is_safe_regex_pattern` function within the `search_code_advanced` component of code-index-mcp. When the server falls back to the `BasicSearchStrategy` (using Python's native `re` module), it fails to properly validate user-supplied regex patterns. An attacker with the ability to invoke the search tool can provide a pattern with nested quantifiers (e.g., `(a+)+
Affected products
- johnhuang316 code-index-mcp <= 2.14.0
Timeline
- 2026-06-03: disclosed
- 2026-06-03: advisory
- 2026-07-10: patched