Junglewise Threat Intelligence

CVE-2026-44694: czlonkowski n8n-mcp authenticated SSRF in webhook and API client

CVE-2026-44694 · Severity: high · CVSS 4 · Published 2026-05-08

Technologies: n8n-mcp (npm). Vendors: npm.

Executive brief

n8n-mcp is a server that allows AI assistants to interact with n8n automation workflows. A security flaw allows authenticated users or malicious AI prompts to force the server into making unauthorized network requests to internal systems. This could lead to the theft of sensitive cloud credentials or the exposure of private internal services, potentially compromising the entire cloud environment.

Technical details

An authenticated Server-Side Request Forgery (SSRF) vulnerability exists in n8n-mcp affecting webhook trigger tools, the n8n API client, and per-request URLs in multi-tenant mode. The vulnerability stems from insufficient validation of URLs, allowing an attacker with MCP session access—or an attacker capable of influencing an LLM via indirect prompt injection—to bypass SSRF protections. This enables the attacker to make requests to internal RFC1918 networks and cloud metadata services (e.g., 169.254.169.254). Because the server returns the response body to the caller, it facilitates immediate exfiltration of IAM, GCP, or Azure managed-identity credentials. The issue is patched in version 2.50.2, which extends SSRF gating to the n8n API client base URL.

Affected products

  • czlonkowski n8n-mcp >= 2.18.7, < 2.50.2

Timeline

  • 2026-05-04: patched: Version 2.50.2 released
  • 2026-05-04: advisory: GitHub Security Advisory GHSA-cmrh-wvq6-wm9r published
  • 2026-05-08: disclosed: CVE-2026-44694 published to NVD

References

Related threats