MCPA-2026-0019
mediumcredential-leakCVSS 4.2
n8n-MCP incorrect authorization exposes default-scope workflow version backups in multi-tenant HTTP mode (CVE-2026-55608)
n8n-mcp before 2.57.4, in multi-tenant HTTP mode (ENABLE_MULTI_TENANT=true), lets an authenticated tenant reach the server's local default-scope workflow_versions backups under certain conditions instead of being confined to its own tenant scope — reading or deleting backups left from a prior single-tenant deployment or migration period, which may contain sensitive workflow logic and node configuration. Fixed in 2.57.4.
Affected packages
| Ecosystem | Package | Affected versions |
|---|---|---|
| npm | n8n-mcp | >= 0, < 2.57.4 |
Identifiers
CVE-2026-55608GHSA-2cf7-hpwf-47h9CWE-200CWE-863
References
- advisory https://github.com/advisories/GHSA-2cf7-hpwf-47h9
- web https://nvd.nist.gov/vuln/detail/CVE-2026-55608
- fix https://github.com/czlonkowski/n8n-mcp/releases/tag/v2.57.4
Timeline
- Published: 2026-07-14