Product
high
advisory
n8n-mcp Unauthenticated Access and Information Disclosure Vulnerability
2 rules 2 TTPsThe n8n-mcp HTTP server had improper authentication in several endpoints, and the health check endpoint leaked sensitive metadata, allowing unauthenticated attackers with network access to disrupt MCP sessions and gather information for further attacks.
n8n-mcp
unauthenticated access
information disclosure
network
2r
2t
high
advisory
n8n-mcp Authenticated SSRF Vulnerability
2 rules 1 TTP 4 IOCsAn authenticated server-side request forgery (SSRF) vulnerability affects the webhook trigger tools and the n8n API client in n8n-mcp versions 2.18.7 to before 2.50.2, allowing attackers to make HTTP requests from the n8n-mcp host to internal services and cloud metadata endpoints, potentially leading to credential theft and internal service enumeration.
n8n-mcp
ssrf
n8n
credential theft
2r
1t
4i