@aborruso/ckan-mcp-server
npm2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting @aborruso/ckan-mcp-serverpage 1 of 1
- CVE-2026-33060MEDIUMCVSS 5.7EG 5.3✓ Fixed in 0.4.852026-03-20
CKAN MCP Server is a tool for querying CKAN open data portals. Versions prior to 0.4.85 provide tools including ckan_package_search and sparql_query that accept a base_url parameter, making HTTP requests to arbitrary endpoints without rest…
- CVE-2026-53509MEDIUMCVSS 5.7EG 5.7✓ Fixed in 0.4.1062026-07-07
@aborruso/ckan-mcp-server: SSRF via base_url allows access to internal networks (Potential fix bypass of CVE-2026-33060) ### Summary A known vulnerability CVE-2026-33060 indicated tools including ckan_package_search and sparql_query that …
Check whether @aborruso/ckan-mcp-server is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for @aborruso/ckan-mcp-server CVEs against the assets you own.
Start Free Scan →