TopVuln

High-risk vulnerability digests

CVE-2026-0621

  • HIGH

Security Bulletin: IBM Rhapsody Systems Engineering is using @modelcontextprotocol/sdk-1.15.0 which is vulnerable to CVE-2026-0621

Details

CVSS v3
7.5
CVSS v4
8.7
NVD published
2026-01-05 21:16:14
EPSS
<0.1% probability · 5.8th percentile — 2026-03-15
Affected versions
cpe:2.3:a:lfprojects:mcp_typescript_sdk:*:*:*:*:*:*:*:*
Summary
Anthropic's MCP TypeScript SDK versions up to and including 1.25.1 contain a regular expression denial of service (ReDoS) vulnerability in the UriTemplate class when processing RFC 6570 exploded array patterns. The dynamically generated regular expression used during URI matching contains nested quantifiers that can trigger catastrophic backtracking on specially crafted inputs, resulting in excessive CPU consumption. An attacker can exploit this by supplying a malicious URI that causes the Node.js process to become unresponsive, leading to a denial of service.
Remediation
Not available in our cache.
Exploit info
https://github.com/modelcontextprotocol/typescript-sdk/issues/965

View on NVD

TopVuln sends digest emails with high-risk CVE picks across multiple authoritative sources—curated with EPSS and AI. Choose daily per-stream emails and optional weekly or monthly roundups.

Subscribe — free email digest or paid plan

Information is aggregated from multiple authoritative sources for convenience; verify with NVD and vendors before operational decisions.