GHSA-75hx-xj24-mqrw
n8n-mcp has unauthenticated session termination and information disclosure in HTTP transport
Quick fix
GHSA-75hx-xj24-mqrw — n8n-mcp: upgrade to the fixed version with the command below.
npm install n8n-mcp@2.47.6Details
### Summary
Several HTTP transport endpoints in n8n-mcp lacked proper authentication, and the health check endpoint exposed sensitive operational metadata without credentials.
### Impact
An unauthenticated attacker with network access to the n8n-mcp HTTP server could disrupt active MCP sessions and gather information useful for further attacks.
### Patches
Fixed in **v2.47.6**. All MCP session endpoints now require Bearer authentication. The health check endpoint has been reduced to a minimal liveness response.
### Workarounds
If you cannot upgrade immediately:
- **Restrict network access** to the HTTP server using firewall rules, reverse proxy IP allowlists, or a VPN so that only trusted clients can reach it. - **Use stdio mode** (`MCP_MODE=stdio`) instead of HTTP mode. The stdio transport does not expose any HTTP endpoints and is unaffected by this vulnerability.
Upgrading to v2.47.6 is still strongly recommended.
### Credit
Reported by @yotampe-pluto.
Are you affected?
Enter the version of the package you're using.