n8n-mcp is vulnerable to Server-Side Request Forgery (SSRF)
83
High Risk
Caller-controlled fragments were interpolated into outbound n8n API paths without strict segment validation and encoding, which opens route manipulation and traversal-style pivots against backend endpoints. Outbound webhook and related HTTP calls still followed redirects by default, so an allowed URL could bounce toward internal or unintended hosts during SSRF checks. Telemetry payloads could retain sensitive fields before persistence. The release validates or encodes path segments, disables redirect following for those outbound flows, and redacts telemetry content before storage.
You are affected if you are using a version that falls within the vulnerable range.
n8n-mcp is vulnerable to Server-Side Request Forgery (SSRF) in versions 0.0.1 - 2.50.0.
Upgrade the n8n-mcp library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant