Skip to content

MCPA-2026-0018

criticalcredential-leakCVSS 9.9

n8n-MCP cross-tenant access to workflow version backups in multi-tenant HTTP deployments (CVE-2026-54052)

n8n-mcp before 2.56.1 does not isolate its locally stored workflow version history per tenant in multi-tenant HTTP deployments (ENABLE_MULTI_TENANT=true): an authenticated tenant can read workflow version snapshots belonging to other tenants — including full node definitions with credential references and authorization headers — and can delete other tenants' stored backups. stdio and single-tenant HTTP deployments are not affected. Fixed in 2.56.1, which isolates stored history per instance and clears previously un-scoped backups.

Affected packages

EcosystemPackageAffected versions
npmn8n-mcp
>= 0, < 2.56.1

Identifiers

CVE-2026-54052GHSA-j6r7-6fhx-77wxCWE-639CWE-862

References

Timeline

  • Published: 2026-07-14

← All advisories