CVE-2026-73844Low· 3.7▾ SunlitCKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, error paths reflect raw upstream response bodies and internal exception messages back to the caller instead of a sanitized, generic message. When the server…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 20.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 3.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.2%
Last analysed / modified upstream
CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, error paths reflect raw upstream response bodies and internal exception messages back to the caller instead of a sanitized, generic message. When the server is pointed at (or redirected/SSRF'd to) a host that returns a non-CKAN response, or when an internal exception occurs, the caller receives verbatim upstream content and internal detail (hostnames, internal IPs, DB errors, stack fragments). This vulnerability is fixed in 0.4.112.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
@aborruso/ckan-mcp-server < 0.4.112Patched in:
@aborruso/ckan-mcp-server 0.4.112Connected by shared product, vendor, weakness, or advisory.
CVE-2026-73846Medium· 6.5CKAN MCP Server is a tool for querying CKAN open data portals
CVE-2026-73845Medium· 5.3CKAN MCP Server is a tool for querying CKAN open data portals
CVE-2026-53509Medium· 5.7CKAN MCP Server is a tool for querying CKAN open data portals
CVE-2025-8852Medium· 4.3A vulnerability was identified in WuKongOpenSource WukongCRM 11.0
CVE-2024-23689High· 8.8Exposure of sensitive information in exceptions in ClichHouse's clickhouse-r2dbc, com.clickhouse:clickhouse-jdbc, and com.clickhouse:clickhouse-client versions less than 0.4.6 allows unauthorized users to gain access to client certificat…
CVE-2023-0833Medium· 4.7A flaw was found in Red Hat's AMQ-Streams, which ships a version of the OKHttp component with an information disclosure flaw via an exception triggered by a header containing an illegal value