CVE-2026-53509
- EPSS 0.22%
- Veröffentlicht 21.08.2026 22:16:38
- Zuletzt bearbeitet 21.08.2026 22:16:38
CKAN MCP Server is a tool for querying CKAN open data portals. A known vulnerability CVE-2026-33060 indicated tools including ckan_package_search and sparql_query that accept a base_url parameter had the risk of making HTTP requests to arbitrary endp...
CVE-2026-73846
- EPSS 0.14%
- Veröffentlicht 14.08.2026 16:56:23
- Zuletzt bearbeitet 17.08.2026 20:16:46
CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, canonicalizeParams in src/utils/cache.ts serializes request parameters with unescaped ampersand, equals-sign, and vertical-bar delimiters, allowing different logical par...
CVE-2026-73845
- EPSS 0.22%
- Veröffentlicht 14.08.2026 16:45:06
- Zuletzt bearbeitet 14.08.2026 18:19:09
CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, the ckan_get_mqa_quality and ckan_get_mqa_quality_details tools in src/tools/quality.ts use isValidMqaServer to validate the server_url parameter with a prefix-only regu...
CVE-2026-73844
- EPSS 0.22%
- Veröffentlicht 14.08.2026 16:41:42
- Zuletzt bearbeitet 18.08.2026 02:17:30
CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, error paths reflect raw upstream response bodies and internal exception messages back to the caller instead of a sanitized, generic message. When the server is pointed a...
CVE-2026-33060
- EPSS 0.29%
- Veröffentlicht 20.03.2026 07:21:30
- Zuletzt bearbeitet 17.04.2026 21:06:02
CKAN MCP Server is a tool for querying CKAN open data portals. Versions prior to 0.4.85 provide tools including ckan_package_search and sparql_query that accept a base_url parameter, making HTTP requests to arbitrary endpoints without restriction. A ...