n8n-mcp is vulnerable to Server-Side Request Forgery (SSRF)
85
High Risk
An improper input validation issue in n8n-mcp SDK embedder deployments allowed user-controlled n8nApiUrl values containing IPv4-mapped IPv6 addresses to bypass SSRF protections that lacked IPv6 checks. This enabled authenticated attackers to force outbound requests to cloud metadata services, localhost endpoints, or private internal networks, while returning response bodies to the caller and forwarding the configured n8nApiKey in the x-n8n-api-key header, resulting in non-blind server-side request forgery and potential credential disclosure.
You are affected if you are using a version that falls within the vulnerable range.
n8n-mcp is vulnerable to Server-Side Request Forgery (SSRF) in versions 2.47.4 - 2.47.13.
Upgrade the n8n-mcp library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant