Skip to content

MCPA-2026-0002

highssrfCVSS 8.3

n8n-mcp path traversal, redirect-following SSRF, and telemetry payload exposure

n8n-mcp before 2.50.1 contained three issues affecting deployments using the n8n API integration: caller-supplied identifiers used unvalidated as URL path segments (path traversal redirecting API-key-bearing requests to other same-origin endpoints, bypassing DISABLED_TOOLS), validated trigger URLs following redirects to otherwise-rejected hosts (non-blind SSRF), and mutation telemetry uploading unredacted operation payloads that can include bearer tokens and webhook secrets. CVSS 8.3.

Affected packages

EcosystemPackageAffected versions
npmn8n-mcp
>= 0, < 2.50.1

Identifiers

GHSA-8g7g-hmwm-6rv2CWE-22CWE-918CWE-201

References

Timeline

  • Published: 2026-05-04

← All advisories