THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-83x6-42hr-jc76 (medium) — CKAN MCP Server: MQA server allowlist bypass via unanchored regex (`isValidMqaServer`)

[GHSA] GHSA-83x6-42hr-jc76 (medium) — CKAN MCP Server: MQA server allowlist bypass via unanchored regex (`isValidMqaServer`)

highgithub_advisoriesPublished 2026-09-02

GHSA-83x6-42hr-jc76 Severity: medium CVE: CVE-2026-73845

CKAN MCP Server: MQA server allowlist bypass via unanchored regex (`isValidMqaServer`)

## Summary

The `ckan_get_mqa_quality` and `ckan_get_mqa_quality_details` tools restrict their `server_url` argument to `dati.gov.it` via a regular expression. The regex is anchored only at the start and places no boundary after the host, so any URL whos

Indicators of compromise

Original source: https://github.com/advisories/GHSA-83x6-42hr-jc76