n8n-mcp is vulnerable to Incorrect Authorization
42
Medium Risk
In multi-tenant HTTP mode, n8n-mcp resolves the tenant scope for its local workflow_versions backup storage from request-derived context. An authenticated tenant whose context resolved to the empty default scope could reach default-scope workflow-version backups instead of being confined to its own tenant, allowing those snapshots to be read or deleted. These backups may contain sensitive workflow configuration. The fix requires a complete tenant context and fails closed when the request maps to the empty default scope, and it rejects requests that supply only one of the tenant headers.
You are affected if you are using a version that falls within the vulnerable range.
n8n-mcp is vulnerable to Incorrect Authorization in versions 2.7.7 - 2.57.3.
Upgrade the n8n-mcp library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant