Executive brief
n8n-mcp is a server that allows AI assistants to interact with n8n automation workflows. In multi-tenant configurations, a security flaw allowed authenticated users to bypass their own environment and execute commands against the service provider's primary n8n instance. This could lead to the unauthorized viewing or modification of sensitive workflows, data tables, and credentials, potentially allowing an attacker to gain full control over the operator's automation environment.
Technical details
An improper access control vulnerability exists in n8n-mcp when configured with ENABLE_MULTI_TENANT=true. The application is designed to select the target n8n instance based on x-n8n-url and x-n8n-key headers provided in each request; however, if these headers are missing or incomplete, the system silently falls back to the process-level N8N_API_URL and N8N_API_KEY intended for the operator. An authenticated tenant can exploit this to execute management calls (reading/writing workflows, accessing data tables) against the operator's instance. In certain configurations, this could escalate to remote code execution if the operator's n8n instance permits Code-node execution. The vulnerability is fixed in version 2.51.2 by enforcing header presence and preventing credential fallback in multi-tenant mode.
Affected products
- czlonkowski n8n-mcp <= 2.51.1
Timeline
- 2026-05-11: patched: Version 2.51.2 released
- 2026-05-12: advisory: GitHub Security Advisory published
- 2026-05-29: disclosed: CVE-2026-45707 published to NVD