Executive brief
n8n-MCP is a tool that helps Claude and other AI assistants build n8n workflows. In multi-tenant mode, an authenticated user could access workflow backups from other tenants or the default system scope, potentially exposing sensitive workflow configurations. This vulnerability only affects multi-tenant HTTP deployments; single-tenant and stdio modes are not impacted.
Technical details
This is an incorrect authorization vulnerability (CWE-863) affecting n8n-MCP's local workflow_versions backup storage in multi-tenant HTTP mode (ENABLE_MULTI_TENANT=true). An authenticated MCP HTTP tenant could bypass tenant isolation and access or delete workflow-version backups stored in the default scope—for example, backups left from a prior single-tenant deployment or migration. The root cause is insufficient tenant context validation when accessing workflow-version resources. The attack requires network reachability to the HTTP endpoint and authentication as a valid tenant; no user interaction is needed. An attacker can read or delete sensitive workflow configurations. The fix (v2.57.4) enforces complete tenant context in multi-tenant mode and fails closed for operations that cannot be attributed to a specific tenant.
Affected products
- czlonkowski n8n-MCP <= 2.57.3
Timeline
- 2026-07-14: disclosed: GHSA-2cf7-hpwf-47h9 published on OSV
- 2026-06-13: patched: Fix released in v2.57.4
- 2026-06-14: other: Commit c1ca1e7 merged with security fix