Romuald Członkowski
6 exploits
Active since Apr 2026
n8n-MCP: Workflow telemetry sanitizer could retain partial values from URL-shaped node parameters
CVSS 6.5
n8n-MCP: Multi-tenant MCP requests fall back to process-level n8n credentials when tenant headers are absent or incomplete
CVSS 8.1
n8n-MCP: Sensitive MCP tool-call arguments logged on authenticated requests in HTTP mode
CVSS 4.3
n8n-MCP: Authenticated SSRF in n8n-mcp webhook and API client paths
CVSS 9.1
n8n-MCP: IPv4-mapped IPv6 addresses bypass SSRF protection in validateUrlSync(), enabling full SSRF for SDK embedders
CVSS 8.5
n8n-MCP <2.47.4 instance-URL Header - Server-Side Request Forgery
CVSS 8.5