N8n Mcp is a specialized integration and workflow automation tool that, despite a narrow product scope, occupies a notable position in automation platforms and enterprise workflow pipelines. The vulnerability profile reflects the complexity inherent to a flexible orchestration platform with broad integration capabilities, though the specific weakness patterns and their structural drivers remain to be fully characterized as the product matures in visibility. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by N8n Mcp over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-54052CRITICAL n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.56.1, in HTTP mode with multi-tenancy enabled through | Jul 15, 2026 | 9.9 | 43 | NO | NO |
CVE-2026-45707HIGH n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.51.2, when ENABLE_MULTI_TENANT=true, the HTTP transpor | May 29, 2026 | 8.1 | 34 | NO | NO |
CVE-2026-42449HIGH n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. In versions 2.47.4 through 2.47.13, the SDK embedder path (N8NDoc | May 7, 2026 | 8.5 | 34 | NO | NO |
CVE-2026-44694CRITICAL n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. From version 2.18.7 to before version 2.50.2, there is an authent | May 8, 2026 | 9.1 | 33 | NO | NO |
CVE-2026-39974HIGH n8n-MCP is a Model Context Protocol (MCP) server that provides AI assistants with comprehensive access to n8n node documentation, properties, and operations. Prior to 2.47.4, an au | Apr 9, 2026 | 8.5 | 29 | NO | NO |
CVE-2026-55608MEDIUM n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.57.4, multi-tenant HTTP mode with ENABLE_MULTI_TENANT= | Jul 15, 2026 | 5.4 | 27 | NO | NO |
CVE-2026-45582MEDIUM n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.51.3, the workflow telemetry sanitizer could retain pa | May 29, 2026 | 6.5 | 26 | NO | NO |
CVE-2026-41495MEDIUM n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to version 2.47.11, when n8n-mcp runs in HTTP transport mod | May 8, 2026 | 5.3 | 23 | NO | NO |
CVE-2026-42282MEDIUM n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to version 2.47.13, when n8n-mcp runs in HTTP transport mod | May 8, 2026 | 4.3 | 22 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by N8n Mcp.
Media articles that mention a CVE ID that affects a product developed by N8n Mcp — matched by CVE ID, not by vendor name.