Remote Code Execution Vulnerability in CKAN MCP Server by OnData
CVE-2026-33060
5.3MEDIUM
What is CVE-2026-33060?
The CKAN MCP Server, designed for querying CKAN open data portals, has a vulnerability in versions prior to 0.4.85 that allows the base_url parameter to accept unrestricted inputs. This flaw enables potential attackers to conduct HTTP requests to arbitrary endpoints, leading to risks such as internal network scanning and cloud metadata theft, particularly exposing IAM credentials. The tools integrated, including ckan_package_search and sparql_query, do not validate the base_url parameter, which opens avenues for SQL and SPARQL injection. Organizations should upgrade to version 0.4.85 or later to mitigate these risks.
Affected Version(s)
ckan-mcp-server < 0.4.85
