CVE-2026-54052
CRITICALn8n-MCP: Cross-tenant access to workflow version backups in multi-tenant HTTP deployments
Title source: cnaDescription
n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.56.1, in HTTP mode with multi-tenancy enabled through ENABLE_MULTI_TENANT=true, n8n-mcp's local workflow version history backups were not isolated per tenant, allowing an authenticated tenant to read workflow version snapshots belonging to other tenants and delete or destroy other tenants' stored backups, including full node definitions, credential references, and authorization headers. This issue is fixed in version 2.56.1.
References (2)
Core 2
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/czlonkowski/n8n-mcp/security/advisories/GHSA-j6r7-6fhx-77wx
X_Refsource_Misc x_refsource_misc
https://github.com/czlonkowski/n8n-mcp/releases/tag/v2.56.1
Scores
CVSS v3
9.9
EPSS
0.0023
EPSS Percentile
13.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-639
CWE-862
Status
published
Products (2)
czlonkowski/n8n-mcp
< 2.56.1
n8n-mcp/n8n-mcp
< 2.56.1
Published
Jul 15, 2026
Tracked Since
Jul 16, 2026