Information Disclosure Vulnerability in CKAN MCP Server by OnData
CVE-2026-73844
3.7LOW
What is CVE-2026-73844?
CKAN MCP Server, designed for querying CKAN open data portals, contains an information disclosure flaw that exposes sensitive internal details. Before version 0.4.112, error handling in the server allowed raw upstream response bodies and internal exception messages to be displayed, revealing critical information such as hostnames, internal IP addresses, database errors, and stack traces. This vulnerability poses a risk when the server interacts with non-CKAN responses or experiences internal exceptions, potentially leading to data exposure. Users are advised to upgrade to version 0.4.112 to mitigate this risk.
Affected Version(s)
ckan-mcp-server < 0.4.112
