VDB
Sign up

package

npm/n8n-mcp

pkg:npm/n8n-mcp

HIGH8.5npm
GHSA-56c3-vfp2-5qqj· CVE-2026-42449

n8n-mcp's IPv4-mapped IPv6 addresses bypass SSRF protection in validateUrlSync(), enabling full SSRF for SDK embedders

Modified: 5/11/2026

HIGH8.2npm
GHSA-75hx-xj24-mqrw

n8n-mcp has unauthenticated session termination and information disclosure in HTTP transport

Modified: 4/10/2026

HIGH8.3npm
GHSA-8g7g-hmwm-6rv2

n8n-mcp affected by path traversal, redirect-following SSRF, and telemetry payload exposure

Modified: 5/8/2026

HIGH8.1npm
GHSA-jxx9-px88-pj69· CVE-2026-45707

n8n-MCP: Multi-tenant MCP requests fall back to process-level n8n credentials when tenant headers are absent or incomplete

Modified: 6/9/2026