highCVSS 8.2Vulnerability

GHSA-75hx-xj24-mqrw

### Summary Several HTTP transport endpoints in n8n-mcp lacked proper authentication, and the health check endpoint exposed sensitive operational metadata without credentials. ### Impact An unauthenticated attacker with network access to the n8n-mcp HTTP server could disrupt active MCP sessions and gather information useful for further attacks. ### Patches Fixed in **v2.47.6**. All MCP session endpoints now require Bearer authentication. The health check endpoint has been reduced to a minimal liveness response. ### Workarounds If you cannot upgrade immediately: - **Restrict network access** to the HTTP server using firewall rules, reverse proxy IP allowlists, or a VPN so that only trusted clients can reach it. - **Use stdio mode** (`MCP_MODE=stdio`) instead of HTTP mode. The stdio transport does not expose any HTTP endpoints and is unaffected by this vulnerability. Upgrading to v2.47.6 is still strongly recommended. ### Credit Reported by @yotampe-pluto.

Properties

ghsa_id
GHSA-75hx-xj24-mqrw
severity
high
summary
n8n-mcp has unauthenticated session termination and information disclosure in HTTP transport
cvss_score
8.2
cve_id
GHSA-75hx-xj24-mqrw
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
is_ghsa_only
true
ghsa_published
2026-04-10T20:59:58Z
source_url
https://github.com/advisories/GHSA-75hx-xj24-mqrw
ghsa_updated
2026-04-10T20:59:59Z

Related Entities (4)

VULNERABLE_TO (1)

[Software]npm/n8n-mcp

AFFECTS (1)

[Software]npm/n8n-mcp

HAS_WEAKNESS (1)

[Weakness]Missing Authentication for Critical Function

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-75hx-xj24-mqrw (CVSS 8.2) — Ninja Signal Threat Intelligence | Ninja Signal