MCPA-2026-0018
criticalcredential-leakCVSS 9.9
n8n-MCP cross-tenant access to workflow version backups in multi-tenant HTTP deployments (CVE-2026-54052)
n8n-mcp before 2.56.1 does not isolate its locally stored workflow version history per tenant in multi-tenant HTTP deployments (ENABLE_MULTI_TENANT=true): an authenticated tenant can read workflow version snapshots belonging to other tenants — including full node definitions with credential references and authorization headers — and can delete other tenants' stored backups. stdio and single-tenant HTTP deployments are not affected. Fixed in 2.56.1, which isolates stored history per instance and clears previously un-scoped backups.
Affected packages
| Ecosystem | Package | Affected versions |
|---|---|---|
| npm | n8n-mcp | >= 0, < 2.56.1 |
Identifiers
CVE-2026-54052GHSA-j6r7-6fhx-77wxCWE-639CWE-862
References
- advisory https://github.com/advisories/GHSA-j6r7-6fhx-77wx
- web https://nvd.nist.gov/vuln/detail/CVE-2026-54052
- fix https://github.com/czlonkowski/n8n-mcp/releases/tag/v2.56.1
Timeline
- Published: 2026-07-14