GHSA-83x6-42hr-jc76

Suggest an improvement
Source
https://github.com/advisories/GHSA-83x6-42hr-jc76
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-83x6-42hr-jc76/GHSA-83x6-42hr-jc76.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-83x6-42hr-jc76
Aliases
Published
2026-09-02T14:52:21Z
Modified
2026-09-02T15:00:10Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
CKAN MCP Server: MQA server allowlist bypass via unanchored regex (`isValidMqaServer`)
Details

Summary

The ckan_get_mqa_quality and ckan_get_mqa_quality_details tools restrict their server_url argument to dati.gov.it via a regular expression. The regex is anchored only at the start and places no boundary after the host, so any URL whose host merely begins with dati.gov.it — or that uses dati.gov.it as URL userinfo before an @ — passes validation while actually targeting an attacker-controlled host.

Affected code

// src/tools/quality.ts
const ALLOWED_SERVER_PATTERNS = [
  /^https?:\/\/(www\.)?dati\.gov\.it/i        // <-- no end anchor / host boundary
];
export function isValidMqaServer(serverUrl: string): boolean {
  return ALLOWED_SERVER_PATTERNS.some(pattern => pattern.test(serverUrl));
}

All of the following return true:

URL Real host
https://dati.gov.it.attacker.com/x dati.gov.it.attacker.com (attacker)
http://dati.gov.it.evil.example/api dati.gov.it.evil.example (attacker)
https://dati.gov.it@attacker.com/x attacker.com (userinfo trick)

After passing this check, server_url flows into getMqaQuality/getMqaQualityDetails, which call makeCkanRequest(serverUrl, "package_show", { id }). The server therefore issues a request to the attacker-controlled host and returns its (parsed) response to the caller.

Impact

  • The intended "dati.gov.it only" trust boundary for the MQA tools is defeated; they can be driven against arbitrary external hosts.
  • The attacker host receives the request (including the dataset_id) and controls the response body that is surfaced back to the model/user — enabling response spoofing and, in an agentic setting, indirect prompt-injection content delivered under the guise of a trusted-portal tool.
  • Contributes to SSRF surface: while makeCkanRequest blocks private/internal IPs, this bypass removes the domain restriction that the code intends to enforce for these tools.

The @-userinfo variant is the most severe form because validation passes on a string whose actual host is fully attacker-chosen.

Proof of concept

poc/mqa-allowlist-poc.mjs runs the verbatim regex over benign and malicious URLs:

accepted  expected_legit  url
true      true            https://dati.gov.it/opendata          <- legit
true      false           https://dati.gov.it.attacker.com/x    <- BYPASS
true      false           http://dati.gov.it.evil.example/api   <- BYPASS
true      false           https://dati.gov.it@attacker.com/x    <- BYPASS

Remediation

Validate the parsed host, not the raw string. For example:

function isValidMqaServer(serverUrl) {
  let u; try { u = new URL(serverUrl); } catch { return false; }
  if (u.protocol !== "https:") return false;
  const h = u.hostname.toLowerCase();
  return h === "dati.gov.it" || h === "www.dati.gov.it";
  // or: h === "dati.gov.it" || h.endsWith(".dati.gov.it")
}

Anchoring the regex end-to-end (/^https:\/\/(www\.)?dati\.gov\.it(\/|$)/i) also closes the suffix trick, but URL-parsing + exact host comparison is the robust fix and also neutralizes the @-userinfo variant.

Database specific
{
    "cwe_ids": [
        "CWE-20",
        "CWE-625",
        "CWE-918"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-09-02T14:52:21Z",
    "nvd_published_at": "2026-08-14T17:20:36Z",
    "severity": "MODERATE"
}
References

Affected packages

npm / @aborruso/ckan-mcp-server

Package

Name
@aborruso/ckan-mcp-server
View open source insights on deps.dev
Purl
pkg:npm/%40aborruso/ckan-mcp-server

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.4.112

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-83x6-42hr-jc76/GHSA-83x6-42hr-jc76.json"