VDB
Sign up
HIGH8.2

GHSA-75hx-xj24-mqrw

n8n-mcp has unauthenticated session termination and information disclosure in HTTP transport

Quick fix

GHSA-75hx-xj24-mqrw — n8n-mcp: upgrade to the fixed version with the command below.

npm install n8n-mcp@2.47.6

Details

### Summary

Several HTTP transport endpoints in n8n-mcp lacked proper authentication, and the health check endpoint exposed sensitive operational metadata without credentials.

### Impact

An unauthenticated attacker with network access to the n8n-mcp HTTP server could disrupt active MCP sessions and gather information useful for further attacks.

### Patches

Fixed in **v2.47.6**. All MCP session endpoints now require Bearer authentication. The health check endpoint has been reduced to a minimal liveness response.

### Workarounds

If you cannot upgrade immediately:

- **Restrict network access** to the HTTP server using firewall rules, reverse proxy IP allowlists, or a VPN so that only trusted clients can reach it. - **Use stdio mode** (`MCP_MODE=stdio`) instead of HTTP mode. The stdio transport does not expose any HTTP endpoints and is unaffected by this vulnerability.

Upgrading to v2.47.6 is still strongly recommended.

### Credit

Reported by @yotampe-pluto.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/n8n-mcp
Introduced in: 0Fixed in: 2.47.6
Fixnpm install n8n-mcp@2.47.6

References