Junglewise Threat Intelligence

CVE-2026-10692: johnhuang316 code-index-mcp ReDoS in search_code_advanced

CVE-2026-10692 · Severity: medium · CVSS 4.3 · Published 2026-06-03

Vendors: PyPI.

Executive brief

Code Index MCP, a tool used to index and search through source code, is vulnerable to a denial-of-service attack. An attacker can provide a specially crafted search pattern that causes the system's search engine to consume excessive CPU resources. This can lead to the service becoming unresponsive, effectively preventing legitimate users from searching their codebase.

Technical details

A Regular Expression Denial of Service (ReDoS) vulnerability exists in the `is_safe_regex_pattern` function within the `search_code_advanced` component of code-index-mcp. When the server falls back to the `BasicSearchStrategy` (using Python's native `re` module), it fails to properly validate user-supplied regex patterns. An attacker with the ability to invoke the search tool can provide a pattern with nested quantifiers (e.g., `(a+)+ Junglewise ) that, when matched against specific file content, triggers catastrophic backtracking. This results in uncontrolled CPU consumption and service exhaustion. The issue is addressed in version 2.14.1 by improving regex safety checks.

Affected products

  • johnhuang316 code-index-mcp <= 2.14.0

Timeline

  • 2026-06-03: disclosed
  • 2026-06-03: advisory
  • 2026-07-10: patched

References