Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
CVE-2026-55608
  • github.com/czlonkowski/n8n-mcp
n8n-MCP: Incorrect authorization can expose default-scope workflow version backups in multi-tenant HTTP mode 15 Jul
  • Fix available
  • Severity - 4.2 (Medium)
CVE-2026-54052
  • github.com/czlonkowski/n8n-mcp
n8n-MCP: Cross-tenant access to workflow version backups in multi-tenant HTTP deployments 15 Jul
  • Fix available
  • Severity - 9.9 (Critical)
GHSA-2cf7-hpwf-47h9
  • npm/n8n-mcp
n8n-MCP: Incorrect authorization can expose default-scope workflow version backups in multi-tenant HTTP mode 14 Jul
  • Fix available
  • Severity - 4.2 (Medium)
GHSA-j6r7-6fhx-77wx
  • npm/n8n-mcp
n8n-MCP: Cross-tenant access to workflow version backups in multi-tenant HTTP deployments 14 Jul
  • Fix available
  • Severity - 9.9 (Critical)
CVE-2026-45582
  • github.com/czlonkowski/n8n-mcp
n8n-MCP: Workflow telemetry sanitizer could retain partial values from URL-shaped node parameters 29 May
  • Fix available
  • Severity - 6.5 (Medium)
CVE-2026-45707
  • github.com/czlonkowski/n8n-mcp
n8n-MCP: Multi-tenant MCP requests fall back to process-level n8n credentials when tenant headers are absent or incomplete 29 May
  • Fix available
  • Severity - 8.1 (High)
GHSA-jxx9-px88-pj69
  • npm/n8n-mcp
n8n-MCP: Multi-tenant MCP requests fall back to process-level n8n credentials when tenant headers are absent or incomplete 18 May
  • Fix available
  • Severity - 8.1 (High)
GHSA-f3rg-xqjj-cj9w
  • npm/n8n-mcp
n8n-MCP: Workflow telemetry sanitizer could retain partial values from URL-shaped node parameters 18 May
  • Fix available
  • Severity - 6.5 (Medium)
CVE-2026-44694
  • github.com/czlonkowski/n8n-mcp
n8n-MCP: Authenticated SSRF in n8n-mcp webhook and API client paths 08 May
  • Fix available
  • Severity - 7.2 (High)
CVE-2026-42282
  • github.com/czlonkowski/n8n-mcp
n8n-MCP: Sensitive MCP tool-call arguments logged on authenticated requests in HTTP mode 08 May
  • Fix available
  • Severity - 4.3 (Medium)
CVE-2026-41495
  • github.com/czlonkowski/n8n-mcp
n8n-MCP Logs Sensitive Request Data on Unauthorized /mcp Requests 08 May
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-8g7g-hmwm-6rv2
  • npm/n8n-mcp
n8n-mcp affected by path traversal, redirect-following SSRF, and telemetry payload exposure 08 May
  • Fix available
  • Severity - 8.3 (High)
GHSA-cmrh-wvq6-wm9r
  • npm/n8n-mcp
n8n-mcp webhook and API client paths has an authenticated SSRF 08 May
  • Fix available
  • Severity - 7.2 (High)
CVE-2026-42449
  • github.com/czlonkowski/n8n-mcp
n8n-MCP: IPv4-mapped IPv6 addresses bypass SSRF protection in validateUrlSync(), enabling full SSRF for SDK embedders 07 May
  • Fix available
  • Severity - 8.5 (High)
GHSA-56c3-vfp2-5qqj
  • npm/n8n-mcp
n8n-mcp's IPv4-mapped IPv6 addresses bypass SSRF protection in validateUrlSync(), enabling full SSRF for SDK embedders 30 Apr
  • Fix available
  • Severity - 8.5 (High)
GHSA-wg4g-395p-mqv3
  • npm/n8n-mcp
n8n-MCP: Sensitive MCP tool-call arguments logged on authenticated requests in HTTP mode 25 Apr
  • Fix available
  • Severity - 4.3 (Medium)