Junglewise Threat Intelligence

CVE-2026-55608: czlonkowski n8n-mcp incorrect authorization in multi-tenant HTTP mode

CVE-2026-55608 · Severity: medium · CVSS 4.2 · Published 2026-07-15

Technologies: n8n-mcp (npm). Vendors: npm.

Executive brief

n8n-MCP is a tool that helps Claude and other AI assistants build n8n workflows. In multi-tenant mode, an authenticated user could access workflow backups from other tenants or the default system scope, potentially exposing sensitive workflow configurations. This vulnerability only affects multi-tenant HTTP deployments; single-tenant and stdio modes are not impacted.

Technical details

This is an incorrect authorization vulnerability (CWE-863) affecting n8n-MCP's local workflow_versions backup storage in multi-tenant HTTP mode (ENABLE_MULTI_TENANT=true). An authenticated MCP HTTP tenant could bypass tenant isolation and access or delete workflow-version backups stored in the default scope—for example, backups left from a prior single-tenant deployment or migration. The root cause is insufficient tenant context validation when accessing workflow-version resources. The attack requires network reachability to the HTTP endpoint and authentication as a valid tenant; no user interaction is needed. An attacker can read or delete sensitive workflow configurations. The fix (v2.57.4) enforces complete tenant context in multi-tenant mode and fails closed for operations that cannot be attributed to a specific tenant.

Affected products

  • czlonkowski n8n-MCP <= 2.57.3

Timeline

  • 2026-07-14: disclosed: GHSA-2cf7-hpwf-47h9 published on OSV
  • 2026-06-13: patched: Fix released in v2.57.4
  • 2026-06-14: other: Commit c1ca1e7 merged with security fix

References

Related threats