Intel

AIKIDO-2026-10517

n8n-mcp is vulnerable to Server-Side Request Forgery (SSRF)

Server-Side Request Forgery (SSRF)GHSA-56c3-vfp2-5qqj Published Apr 23, 2026

85

High Risk

This Affects:

JSn8n-mcp
2.47.4 - 2.47.13
Fixed in 2.47.14
Are you affected? Scan for Free

TL;DR

An improper input validation issue in n8n-mcp SDK embedder deployments allowed user-controlled n8nApiUrl values containing IPv4-mapped IPv6 addresses to bypass SSRF protections that lacked IPv6 checks. This enabled authenticated attackers to force outbound requests to cloud metadata services, localhost endpoints, or private internal networks, while returning response bodies to the caller and forwarding the configured n8nApiKey in the x-n8n-api-key header, resulting in non-blind server-side request forgery and potential credential disclosure.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

n8n-mcp is vulnerable to Server-Side Request Forgery (SSRF) in versions 2.47.4 - 2.47.13.

How to fix this

Upgrade the n8n-mcp library to the patch version.