Executive brief
n8n is a workflow automation tool used to connect different software services. A security flaw in the MCP Client node allows authorized users to bypass internal network protections. This could allow an attacker to access sensitive internal company services or data that should normally be restricted from the n8n server.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in n8n's MCP Client node. The component fails to route requests through the platform's built-in SSRF protection layer and does not perform IP address pinning on resolved hostnames. An authenticated attacker with permissions to create or edit workflows can provide a malicious endpoint, forcing the server to connect to internal or link-local addresses. This allows the attacker to read responses from internal services that are otherwise unreachable. The issue is fixed in versions 2.31.5 and 2.32.1.
Affected products
- n8n-io n8n < 2.31.5, >= 2.32.0 < 2.32.1
Timeline
- 2026-07-22: disclosed
- 2026-07-22: advisory
- 2026-07-22: patched