VulnWatch VulnWatch
← Back to dashboard
Medium nvd · CVE-2026-55608

CVE-2026-55608: n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior

Published Jul 15, 2026 CVSS 4.2

n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.57.4, multi-tenant HTTP mode with ENABLE_MULTI_TENANT=true could allow an authenticated tenant to access default-scope workflow_versions backups instead of being confined to the tenant scope, exposing or deleting workflow-version backups from prior single-tenant deployments or migrations. This issue is fixed in version 2.57.4.

Affected AI Products

mcp server
Get the weekly digest. Every Monday: top AI security stories of the week. Free.