Security: czlonkowski/n8n-mcp
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Incomplete IPv6 link-local address filtering in outbound URL validationGHSA-2x5j-hrmv-ccrq published
Aug 9, 2026 by czlonkowskiLow -
Incorrect authorization can expose default-scope workflow version backups in multi-tenant HTTP modeGHSA-2cf7-hpwf-47h9 published
Jun 14, 2026 by czlonkowskiModerate -
Cross-tenant access to workflow version backups in multi-tenant HTTP deploymentsGHSA-j6r7-6fhx-77wx published
Jun 3, 2026 by czlonkowskiCritical -
Workflow telemetry sanitizer could retain partial values from URL-shaped node parametersGHSA-f3rg-xqjj-cj9w published
May 11, 2026 by czlonkowskiModerate -
Multi-tenant MCP requests fall back to process-level n8n credentials when tenant headers are absent or incompleteGHSA-jxx9-px88-pj69 published
May 12, 2026 by czlonkowskiHigh -
Authenticated SSRF in n8n-mcp webhook and API client pathsGHSA-cmrh-wvq6-wm9r published
May 4, 2026 by czlonkowskiHigh -
Path traversal, redirect-following SSRF, and telemetry payload exposure in n8n-mcpGHSA-8g7g-hmwm-6rv2 published
May 4, 2026 by czlonkowskiHigh -
IPv4-mapped IPv6 addresses bypass SSRF protection in validateUrlSync(), enabling full SSRF for SDK embeddersGHSA-56c3-vfp2-5qqj published
Apr 22, 2026 by czlonkowskiHigh -
Sensitive MCP tool-call arguments logged on authenticated requests in HTTP modeGHSA-wg4g-395p-mqv3 published
Apr 21, 2026 by czlonkowskiModerate -
Sensitive Request Data Logged on Unauthorized /mcp RequestsGHSA-pfm2-2mhg-8wpx published
Apr 20, 2026 by czlonkowskiModerate