Executive brief
n8n is a workflow automation platform that allows users to create and run complex automations. The MCP Client node in n8n has a vulnerability that bypasses the platform's Server-Side Request Forgery (SSRF) protection, a critical security control that prevents unauthorized internal network access. An authenticated user could exploit this to access internal services and read sensitive data that should have been protected.
Technical details
The MCP Client node sends requests to user-supplied endpoints without routing them through n8n's SSRF protection layer and without pinning the resolved address, violating the expected security boundary. This is a Server-Side Request Forgery (CWE-918) vulnerability requiring authentication and workflow creation/edit privileges. An authenticated attacker can craft a workflow that directs the MCP Client node to connect to internal or otherwise blocked hosts, bypassing network-level access controls and exfiltrating responses that reveal internal service information. The vulnerability affects n8n versions prior to 2.31.5 and 2.32.0 through 2.32.0 (fixed in 2.31.5 and 2.32.1).
Affected products
- n8n n8n < 2.31.5, 2.32.0
Timeline
- 2026-07-22: disclosed
- 2026-07-22: patched: Fixed in versions 2.31.5 and 2.32.1