n8n-mcp vulnerabilities
CVEs whose affected-version data names the n8n-mcp package (npm). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-55608Medium· 4.2n8n-MCP: Incorrect authorization can expose default-scope workflow version backups in multi-tenant HTTP mode
n8n-MCP: Incorrect authorization can expose default-scope workflow version backups in multi-tenant HTTP mode
▾ Sunlitn8n-mcp · n8n-mcpEPSS 0.28%via GHSA
CVE-2026-54052Critical· 9.9n8n-MCP: Cross-tenant access to workflow version backups in multi-tenant HTTP deployments
n8n-MCP: Cross-tenant access to workflow version backups in multi-tenant HTTP deployments
▾ Midnightn8n-mcp · n8n-mcpEPSS 0.39%via GHSA