Vulnerability  ·  2026-09-22

CKAN MCP Server: third SSRF bypass reaches cloud metadata (IMDS) (CVSS 5.7)

VulnerabilityMedium impactGlobalCVE-2026-61612
Published 2026-09-21. This is the third bypass of the same guard, and strictly worse than CVE-2026-53509: it reaches cloud metadata (IMDS) in addition to loopback.
In a cloud-deployed AI/MCP environment, SSRF to 169.254.169.254 can expose instance-role credentials to the agent/tool — turning a data-portal MCP tool into a cloud-credential exfil channel.
The validateServerUrl SSRF guard (previously patched for CVE-2026-33060 / CVE-2026-53509) validates only the hostname string and never resolves DNS, so a hostname resolving internally bypasses the block. An agent can be steered to send requests to instance metadata.
ondata/ckan-mcp-server (CKAN MCP Server) < 0.4.108
Upgrade to v0.4.108 (commit bb7439b5; GHSA-798p-78g2-v556).
NVD CVE-2026-61612Advisory GHSA-798p-78g2-v556
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →