CVE-2026-0621 | Anthropic MCP TypeScript SDK up to 1.25.1 URI UriTemplate redos (Issue 965 / EUVD-2026-0800)
A vulnerability identified as problematic has been detected in Anthropic MCP TypeScript SDK up to 1.25.1. The impacted element is the function UriTemplate of the component URI Handler. Performing a manipulation results in inefficient regular expression complexity.
This vulnerability is identified as CVE-2026-0621. The attack can be initiated remotely. There is not any exploit available.