CVE-2026-55608
- EPSS 0.16%
- Veröffentlicht 15.07.2026 20:35:29
- Zuletzt bearbeitet 17.07.2026 17:11:08
n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.57.4, multi-tenant HTTP mode with ENABLE_MULTI_TENANT=true could allow an authenticated tenant to access default-scope workf...
CVE-2026-54052
- EPSS 0.23%
- Veröffentlicht 15.07.2026 20:34:10
- Zuletzt bearbeitet 18.07.2026 03:16:37
n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.56.1, in HTTP mode with multi-tenancy enabled through ENABLE_MULTI_TENANT=true, n8n-mcp's local workflow version history bac...
CVE-2026-45582
- EPSS 0.26%
- Veröffentlicht 29.05.2026 13:37:30
- Zuletzt bearbeitet 21.07.2026 12:10:00
n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.51.3, the workflow telemetry sanitizer could retain partial fragments of URL-shaped node parameters before sending workflow ...
CVE-2026-45707
- EPSS 0.24%
- Veröffentlicht 29.05.2026 13:35:42
- Zuletzt bearbeitet 21.07.2026 12:10:00
n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.51.2, when ENABLE_MULTI_TENANT=true, the HTTP transport documents that the target n8n instance is selected per-request from ...
CVE-2026-44694
- EPSS 0.24%
- Veröffentlicht 08.05.2026 19:12:05
- Zuletzt bearbeitet 14.05.2026 18:10:06
n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. From version 2.18.7 to before version 2.50.2, there is an authenticated server-side request forgery vulnerability affecting the webhook...
CVE-2026-42282
- EPSS 0.25%
- Veröffentlicht 08.05.2026 19:07:13
- Zuletzt bearbeitet 14.05.2026 18:07:37
n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to version 2.47.13, when n8n-mcp runs in HTTP transport mode, authenticated MCP tools/call requests had their full arguments and ...
CVE-2026-41495
- EPSS 0.26%
- Veröffentlicht 08.05.2026 18:58:24
- Zuletzt bearbeitet 14.05.2026 18:06:34
n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to version 2.47.11, when n8n-mcp runs in HTTP transport mode, incoming requests to the POST /mcp endpoint had their request metad...
CVE-2026-42449
- EPSS 0.21%
- Veröffentlicht 07.05.2026 20:46:29
- Zuletzt bearbeitet 14.05.2026 17:37:37
n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. In versions 2.47.4 through 2.47.13, the SDK embedder path (N8NDocumentationMCPServer constructor, getN8nApiClient(), and validateInstan...
CVE-2026-39974
- EPSS 0.32%
- Veröffentlicht 09.04.2026 17:16:30
- Zuletzt bearbeitet 20.04.2026 18:32:37
n8n-MCP is a Model Context Protocol (MCP) server that provides AI assistants with comprehensive access to n8n node documentation, properties, and operations. Prior to 2.47.4, an authenticated Server-Side Request Forgery in n8n-mcp allows a caller hol...