Remote Code Execution Vulnerability in CKAN MCP Server by OnData
CVE-2026-33060

5.3MEDIUM

Key Information:

Vendor

Ondata

Vendor
CVE Published:
20 March 2026

What is CVE-2026-33060?

The CKAN MCP Server, designed for querying CKAN open data portals, has a vulnerability in versions prior to 0.4.85 that allows the base_url parameter to accept unrestricted inputs. This flaw enables potential attackers to conduct HTTP requests to arbitrary endpoints, leading to risks such as internal network scanning and cloud metadata theft, particularly exposing IAM credentials. The tools integrated, including ckan_package_search and sparql_query, do not validate the base_url parameter, which opens avenues for SQL and SPARQL injection. Organizations should upgrade to version 0.4.85 or later to mitigate these risks.

Affected Version(s)

ckan-mcp-server < 0.4.85

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.