Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-798p-78g2-v556
  • npm/@aborruso/ckan-mcp-server
@aborruso/ckan-mcp-server has SSRF via DNS-name → internal IP — incomplete fix of CVE-2026-53509 22 Sep
  • Fix available
  • Severity - 5.7 (Medium)
GHSA-78x9-fhhx-v2g6
  • npm/@aborruso/ckan-mcp-server
CKAN MCP Server: Cache-key canonicalization collision enables cache confusion / poisoning 03 Sep
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-6f9w-9hf2-5rg3
  • npm/@aborruso/ckan-mcp-server
CKAN MCP Server: Information disclosure via verbose error reflection 03 Sep
  • Fix available
  • Severity - 3.7 (Low)
GHSA-83x6-42hr-jc76
  • npm/@aborruso/ckan-mcp-server
CKAN MCP Server: MQA server allowlist bypass via unanchored regex (`isValidMqaServer`) 02 Sep
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-g84h-j7jj-x32p
  • npm/@aborruso/ckan-mcp-server
@aborruso/ckan-mcp-server: SSRF via base_url allows access to internal networks (Potential fix bypass of CVE-2026-33060) 07 Jul
  • Fix available
  • Severity - 5.7 (Medium)
GHSA-3xm7-qw7j-qc8v
  • npm/@aborruso/ckan-mcp-server
SSRF in @aborruso/ckan-mcp-server via base_url allows access to internal networks 18 Mar
  • Fix available
  • Severity - 5.7 (Medium)