Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-0621

Опубликовано: 05 янв. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

Anthropic's MCP TypeScript SDK versions up to and including 1.25.1 contain a regular expression denial of service (ReDoS) vulnerability in the UriTemplate class when processing RFC 6570 exploded array patterns. The dynamically generated regular expression used during URI matching contains nested quantifiers that can trigger catastrophic backtracking on specially crafted inputs, resulting in excessive CPU consumption. An attacker can exploit this by supplying a malicious URI that causes the Node.js process to become unresponsive, leading to a denial of service.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:lfprojects:mcp_typescript_sdk:*:*:*:*:*:*:*:*
Версия до 1.25.1 (включая)

EPSS

Процентиль: 3%
0.00016
Низкий

7.5 High

CVSS3

Дефекты

CWE-1333

Связанные уязвимости

github
около 1 месяца назад

Anthropic's MCP TypeScript SDK has a ReDoS vulnerability

EPSS

Процентиль: 3%
0.00016
Низкий

7.5 High

CVSS3

Дефекты

CWE-1333