PT-2026-96188 · Npm · Ckan-Mcp-Server

CVE-2026-61612

·

Published

2026-03-18

·

Updated

2026-10-07

CVSS v3.1

5.7

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions @aborruso/ckan-mcp-server (affected versions not specified)
Description Tools such as ckan package search, sparql query, and ckan datastore search sql accept a base url (or server url) parameter that allows making HTTP requests to arbitrary endpoints without sufficient restriction. The server fails to properly validate the hostname, allowing attackers to bypass filters using aliases like ip6-localhost or ip6-loopback to connect to local or private addresses. This can lead to internal network scanning, theft of cloud metadata (such as IAM credentials via IMDS at 169.254.169.254), and potential SQL or SPARQL injection via unsanitized query parameters. Exploitation requires prompt injection to control the base url parameter while the victim's AI assistant is connected to the server.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. Validate the base url against a configurable allowlist of permitted CKAN portals. Block private IP ranges (RFC 1918 and link-local) and cloud metadata endpoints (169.254.169.254). Sanitize SQL input for datastore queries and implement an allowlist for SPARQL endpoints. Restrict the use of the base url and server url parameters in the ckan package search, sparql query, and ckan datastore search sql tools until a patch is applied.

Exploit

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61612
GHSA-3XM7-QW7J-QC8V
GHSA-798P-78G2-V556
GHSA-G84H-J7JJ-X32P

Affected Products

Ckan-Mcp-Server