{"id":"GHSA-g84h-j7jj-x32p","summary":"@aborruso/ckan-mcp-server: SSRF via base_url allows access to internal networks (Potential fix bypass of CVE-2026-33060)","details":"### Summary\nA known vulnerability CVE-2026-33060 indicated tools including ckan_package_search and sparql_query that accept a base_url parameter had the risk of making HTTP requests to arbitrary endpoints without restriction. A fix was applied to filter out ip addresses. However, a method to bypass exists.\n\n### Details\nCKAN MCP Server validates caller-supplied CKAN server URLs by inspecting only the parsed hostname string before issuing outbound HTTP requests. In `src/utils/http.ts`, hostname aliases such as `ip6-localhost` are not equal to `localhost`, are not dotted IPv4 literals, and are not bracketed IPv6 literals, so they pass the SSRF filter but can resolve to loopback when the server performs the request. A remote MCP caller that can invoke CKAN tools with a `server_url` can therefore make the server connect to local or private addresses and, for CKAN-shaped responses, receive response-derived data.\n\n### Fix\nReplaced the single `hostname === 'localhost'` check with a blocked-hostname `Set` covering `ip6-localhost` and `ip6-loopback`. Patched in commit `c761045a1b7c5f40d2626540dd2ef1d4feb91f8c`.\n\n---\n@aborruso/ckan-mcp-server thanks **hibrian827** for responsibly disclosing this issue.","aliases":["CVE-2026-53509"],"modified":"2026-09-23T03:56:40.257791154Z","published":"2026-07-07T19:35:57Z","related":["CVE-2026-53509","CVE-2026-61612"],"database_specific":{"github_reviewed_at":"2026-07-07T19:35:57Z","nvd_published_at":null,"cwe_ids":["CWE-918"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/ondata/ckan-mcp-server/security/advisories/GHSA-g84h-j7jj-x32p"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-3xm7-qw7j-qc8v"},{"type":"PACKAGE","url":"https://github.com/ondata/ckan-mcp-server"},{"type":"WEB","url":"https://github.com/ondata/ckan-mcp-server/releases/tag/v0.4.106"}],"affected":[{"package":{"name":"@aborruso/ckan-mcp-server","ecosystem":"npm","purl":"pkg:npm/%40aborruso/ckan-mcp-server"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.4.106"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-g84h-j7jj-x32p/GHSA-g84h-j7jj-x32p.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N"}]}