CVE Tools

N8N-MCP

12 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for N8N-MCP, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.

N8N-MCP CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
N8N-MCP CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-030
2026-043
2026-057
2026-060
2026-072
2026-080
2026-090

Severity

How the 12 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical222%
  • High333%
  • Medium444%

Latest CVEs

The 12 most recently published vulnerabilities affecting N8N-MCP.

  1. CVE-2026-55608n8n-MCP: Incorrect authorization can expose default-scope workflow version backups in multi-tenant HTTP mode4.2
  2. CVE-2026-54052n8n-MCP: Cross-tenant access to workflow version backups in multi-tenant HTTP deployments9.9
  3. CVE-2026-45582n8n-MCP: Workflow telemetry sanitizer could retain partial values from URL-shaped node parameters6.5
  4. CVE-2026-45707n8n-MCP: Multi-tenant MCP requests fall back to process-level n8n credentials when tenant headers are absent or incomplete8.1
  5. CVE-2026-44694n8n-MCP: Authenticated SSRF in n8n-mcp webhook and API client paths9.1
  6. CVE-2026-42282n8n-MCP: Sensitive MCP tool-call arguments logged on authenticated requests in HTTP mode4.3
  7. CVE-2026-41495n8n-MCP Logs Sensitive Request Data on Unauthorized /mcp Requests5.3
  8. GHSA-8g7g-hmwm-6rv2n8n-mcp affected by path traversal, redirect-following SSRF, and telemetry payload exposure—
  9. CVE-2026-42449n8n-MCP: IPv4-mapped IPv6 addresses bypass SSRF protection in validateUrlSync(), enabling full SSRF for SDK embedders8.5
  10. GHSA-75hx-xj24-mqrwn8n-mcp has unauthenticated session termination and information disclosure in HTTP transport—
  11. CVE-2026-39974n8n-MCP has an Authenticated SSRF via instance-URL header in multi-tenant HTTP mode8.5
  12. GHSA-4ggg-h7ph-26qrn8n-mcp has authenticated SSRF via instance-URL header in multi-tenant HTTP mode—

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store