Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-54052— n8n-MCP: Cross-tenant access to workflow version backups in multi-tenant HTTP deployments

Quick assessment

Affected
czlonkowski n8n-mcp
Exploitation
Public or AI PoC available; prioritize validation
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

czlonkowski n8n-mcp是czlonkowski的MCP 工具。 czlonkowski n8n-mcp 2.56.1之前版本存在授权问题漏洞,该漏洞源于在多租户HTTP模式下,工作流版本历史备份未按租户隔离,可能导致已认证的用户读取或删除其他租户的工作流版本快照、节点定义、凭据引用及授权标头。

CVSS 9.9 · Critical EPSS 0.39% · P31

Possible ATT&CK Techniques 1 AI

T1530 · Data from Cloud Storage

Affected Version Matrix 1

VendorProduct Version RangeStatus
czlonkowski n8n-mcp < 2.56.1 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-54052

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
n8n-MCP: Cross-tenant access to workflow version backups in multi-tenant HTTP deployments
Source: CVE Program / CVE List V5
Vulnerability Description
n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.56.1, in HTTP mode with multi-tenancy enabled through ENABLE_MULTI_TENANT=true, n8n-mcp's local workflow version history backups were not isolated per tenant, allowing an authenticated tenant to read workflow version snapshots belonging to other tenants and delete or destroy other tenants' stored backups, including full node definitions, credential references, and authorization headers. This issue is fixed in version 2.56.1.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
通过用户控制密钥绕过授权机制
Source: CVE Program / CVE List V5
Vulnerability Title
czlonkowski n8n-mcp 授权问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
czlonkowski n8n-mcp是czlonkowski的MCP 工具。 czlonkowski n8n-mcp 2.56.1之前版本存在授权问题漏洞,该漏洞源于在多租户HTTP模式下,工作流版本历史备份未按租户隔离,可能导致已认证的用户读取或删除其他租户的工作流版本快照、节点定义、凭据引用及授权标头。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
czlonkowski n8n-mcp < 2.56.1 -

II. Public POCs for CVE-2026-54052

# POC Description Source Link Shenlong Link
AI-Generated POC Premium
Qwen3.6-35B-A3B · 7096 chars
Pro+ exclusive includes:
Vulnerability reproduction recording (real sandbox build + trigger, exclusive)
In-depth vulnerability mechanism
Trigger conditions & impact
Full executable POC code
Exploit chain & mitigation
POC zip download
100+ AI POC generations per month

III. Intelligence Information for CVE-2026-54052

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-54052 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-54052

No comments yet


Leave a comment