PT-2026-1337 · Anthropic · Mcp Typescript Sdk

Weblover

·

Publicado

2026-01-05

·

Atualizado

2026-02-02

·

CVE-2026-0621

CVSS v4.0

8.7

Alta

VetorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Anthropic's MCP TypeScript SDK versions up to and including 1.25.1
Description The software contains a regular expression denial of service (ReDoS) issue within the UriTemplate class when handling RFC 6570 exploded array patterns. The dynamically generated regular expression used for URI matching includes nested quantifiers, which can lead to catastrophic backtracking when processing specifically crafted inputs. This can cause excessive CPU usage, potentially making the Node.js process unresponsive and resulting in a denial of service. An attacker can exploit this by providing a malicious URI.
Recommendations Upgrade to version 1.25.2.

Exploit

Correção

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-0621
GHSA-8R9Q-7V3J-JR4G

Produtos afetados

Mcp Typescript Sdk