Executive brief
n8n-mcp is a server that allows AI assistants to interact with n8n automation workflows. In multi-tenant configurations, a security flaw allowed one user to access, read, or delete the workflow backups belonging to other users. This could lead to the exposure of sensitive information, including authorization headers and credential references used in automated business processes.
Technical details
A broken access control vulnerability (CWE-639/CWE-862) exists in n8n-mcp when running in HTTP mode with ENABLE_MULTI_TENANT=true. The local workflow version history backups were not properly scoped to individual tenants, allowing an authenticated tenant to perform unauthorized CRUD operations on snapshots belonging to others. These snapshots contain full node definitions, which may include sensitive credential references and authorization headers. The vulnerability is exploited via network requests to the workflow version tool. A fix is available in version 2.56.1, which implements instance-based isolation for backups.
Affected products
- czlonkowski n8n-mcp < 2.56.1
Timeline
- 2026-06-02: patched: Version 2.56.1 released
- 2026-06-03: advisory: GitHub Security Advisory published
- 2026-07-15: disclosed: NVD publication date