5 Total advisories
5 Vulnerabilities
0 Malware
Dependency scanning
Check whether @aborruso/ckan-mcp-server is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
MEDIUM 5.7
CVE-2026-53509
@aborruso/ckan-mcp-server: SSRF via base_url allows access to internal networks (Potential fix bypass of CVE-2026-33060)
MEDIUM 6.5
CVE-2026-73846
CKAN MCP Server: Cache-key canonicalization collision enables cache confusion / poisoning
LOW 3.7
CVE-2026-73844
CKAN MCP Server: Information disclosure via verbose error reflection
MEDIUM 5.3
CVE-2026-73845
CKAN MCP Server: MQA server allowlist bypass via unanchored regex (`isValidMqaServer`)
MEDIUM 5.7
CVE-2026-33060
SSRF in @aborruso/ckan-mcp-server via base_url allows access to internal networks
Browse more npm advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes