CKAN MCP Server: Multiple security vulnerabilities in allowlist and cache
Two critical vulnerabilities discovered in the CKAN MCP Server npm package: an unanchored regex bypass in the MQA server allowlist validation that enables SSRF and prompt injection attacks, and a cache-key canonicalization collision that allows cache poisoning to deliver spoofed responses to legitimate queries.
Disclosed 2 September 2026 · Record updated 13 September 2026
Impact
Attackers can bypass the dati.gov.it domain restriction via regex bypass or userinfo injection to perform SSRF attacks and indirect prompt injection. Additionally, cache key collisions enable cache poisoning to serve attacker-controlled responses to legitimate queries, undermining data integrity.
Our coverage
No articles linked to this incident yet.
Sources
- github.comhttps://github.com/advisories/GHSA-83x6-42hr-jc76
- github.comhttps://github.com/advisories/GHSA-78x9-fhhx-v2g6
