GHSA-798p-78g2-v556: @aborruso/ckan-mcp-server has SSRF via DNS-name → internal IP — incomplete fix of CVE-2026-53509
Summary
A server package called `@aborruso/ckan-mcp-server` has a security flaw called SSRF (server-side request forgery, where a server makes requests to places it shouldn't). The flaw exists in a validation function that checks hostnames but never resolves them using DNS (the system that translates website names into IP addresses). An attacker can supply a hostname that looks safe but actually resolves to internal addresses like `127.0.0.1` or `169.254.169.254` (cloud metadata), allowing them to steal internal data. This bug is still present in the latest version (0.4.107) and has bypassed two previous attempted fixes.
Vulnerability Details
EPSS: 0.2%
Yes
September 22, 2026
Classification
Affected Vendors
Affected Packages
Original source: https://github.com/advisories/GHSA-798p-78g2-v556
First tracked: September 22, 2026 at 02:01 PM
Classified by LLM (prompt v3) · confidence: 92%