CVE-2026-53509 | ondata ckan-mcp-server up to 0.4.105 Hostname Validation src/utils/http.ts base_url server-side request forgery

SecurityVulns

A vulnerability was found in ondata ckan-mcp-server up to 0.4.105. It has been declared as problematic. The affected element is an unknown function of the file src/utils/http.ts of the component Hostname Validation. Executing a manipulation of the argument base_url can lead to server-side request forgery.

This vulnerability is handled as CVE-2026-53509. The attack can be executed remotely. There is not any exploit available.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More