← Späť na vyhľadávanie CVE

CVE-2026-54052

n8n-MCP

Popis

n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.56.1, in HTTP mode with multi-tenancy enabled through ENABLE_MULTI_TENANT=true, n8n-mcp-s local workflow version history backups were not isolated per tenant, allowing an authenticated tenant to read workflow version snapshots belonging to other tenants and delete or destroy other tenants- stored backups, including full node definitions, credential references, and authorization headers. This issue is fixed in version 2.56.1.

CVSS 9.9EPSS 0.22799999999999998%Riziko 1.01
Zobraziť zdroj
Zverejnené
2026-07-15 21:16:54
Dotknuté verzie
<2.56.1
Typ
Kritický softvér
Vektor
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L