Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 14 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 14 Aug 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, the ckan_get_mqa_quality and ckan_get_mqa_quality_details tools in src/tools/quality.ts use isValidMqaServer to validate the server_url parameter with a prefix-only regular expression for dati.gov.it, allowing suffix-host and URL-userinfo values to target an attacker-controlled host and return a spoofed response. This issue is fixed in version 0.4.112. | |
| Title | CKAN MCP Server: MQA server allowlist bypass via unanchored regex (`isValidMqaServer`) | |
| Weaknesses | CWE-20 CWE-625 CWE-918 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-14T18:06:04.170Z
Reserved: 2026-08-13T17:44:28.643Z
Link: CVE-2026-73845
Updated: 2026-08-14T17:41:40.075Z
Status : Received
Published: 2026-08-14T17:20:36.820
Modified: 2026-08-14T18:19:09.740
Link: CVE-2026-73845
No data.
OpenCVE Enrichment
No data.