VDB
Sign up
LOW3.7

GHSA-6f9w-9hf2-5rg3

CKAN MCP Server: Information disclosure via verbose error reflection

Quick fix

GHSA-6f9w-9hf2-5rg3 — @aborruso/ckan-mcp-server: upgrade to the fixed version with the command below.

npm install @aborruso/ckan-mcp-server@0.4.112

Details

## Summary

Error paths reflect raw upstream response bodies and internal exception messages back to the caller instead of a sanitized, generic message. When the server is pointed at (or redirected/SSRF'd to) a host that returns a non-CKAN response, or when an internal exception occurs, the caller receives verbatim upstream content and internal detail (hostnames, internal IPs, DB errors, stack fragments).

## Affected code

`src/utils/http.ts` — the entire decoded upstream body is embedded in the thrown error, which `formatCkanError` returns to the tool result:

```js } else { throw new CkanApiError( `CKAN API returned success=false: ${JSON.stringify(decodedData)}`, // full body reflected undefined, action ); } ```

`src/worker.ts` — the catch-all handler returns the raw `Error.message` in the JSON-RPC `data` field:

```js return new Response(JSON.stringify({ jsonrpc: '2.0', error: { code: -32603, message: 'Internal error', data: error instanceof Error ? error.message : String(error) }, // raw internal message id: null }), { status: 500, ... }); ```

## Impact

- Reflects arbitrary upstream response content to the caller. Combined with the SSRF vectors (advisories #01/#06), an attacker can use this as the *read* channel: point the server at an internal endpoint and receive its body inside the `success=false` error string (turning otherwise-blind SSRF into a semi-blind/return-value SSRF for any host that reaches the guards). - Leaks internal operational detail via exception messages: node error codes and target addresses (e.g. `ECONNREFUSED 169.254.169.254:80`), which confirm internal reachability and infrastructure, and any stack/path fragments an upstream includes. - Aids reconnaissance and error-oracle attacks against the deployment.

Severity is Low on its own (the server holds no credentials of its own and sends no auth upstream), but it meaningfully amplifies the SSRF findings by providing a response-content channel.

## Proof of concept

`poc/error-disclosure-poc.mjs` reproduces both paths and shows an upstream body (containing a simulated DB error with an internal IP) and an internal `ECONNREFUSED 169.254.169.254` message being reflected to the caller.

## Remediation

- Return generic, action-scoped error messages to the caller; log the detailed upstream body/exception server-side only. - Do not embed `JSON.stringify(decodedData)` in caller-visible errors; cap and redact any reflected content. - In the Workers catch-all, omit `error.message` from the response `data` (or replace with a correlation id) in production.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@aborruso/ckan-mcp-server
Introduced in: 0Fixed in: 0.4.112
Fixnpm install @aborruso/ckan-mcp-server@0.4.112

References