PT-2026-72066 · Unknown · Ckan-Mcp-Server

CVE-2026-73845

·

Published

2026-08-14

·

Updated

2026-09-02

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions CKAN MCP Server versions prior to 0.4.112
Description The ckan get mqa quality() and ckan get mqa quality details() functions in src/tools/quality.ts use the isValidMqaServer function to validate the server url parameter. Because the validation uses a prefix-only regular expression for dati.gov.it, it is possible to bypass the allowlist using suffix-host or URL-userinfo values. This allows the request to target a host controlled by an attacker, which can then return a spoofed response.
Recommendations Update to version 0.4.112.

Exploit

Fix

SSRF

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73845
GHSA-83X6-42HR-JC76

Affected Products

Ckan-Mcp-Server