Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-54052: n8n-MCP: Cross-Tenant Access to Workflow Backups in Multi-Tenant Deployments

GHSA-j6r7-6fhx-77wx CVE-2026-54052 CVE-2026-54052 CVE-2026-54052
Summary

In multi-tenant n8n-MCP deployments, an authenticated tenant could access and delete other tenants' workflow backup data. This is fixed in version 2.56.1. To protect your data, upgrade to the latest version or disable the workflow version tool if you cannot upgrade immediately.

What to do
  • Update GitHub Actions n8n-mcp to version 2.56.1.
Affected software
Ecosystem VendorProductAffected versions
npm GitHub Actions n8n-mcp <= 2.56.0
Fix: upgrade to 2.56.1
czlonkowski n8n-mcp < 2.56.1
n8n-mcp n8n-mcp < 2.56.1
cpe:2.3:a:n8n-mcp:n8n-mcp:*:*:*:*:*:*:*:*
Original title
n8n-MCP: Cross-tenant access to workflow version backups in multi-tenant HTTP deployments
Original description
n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.56.1, in HTTP mode with multi-tenancy enabled through ENABLE_MULTI_TENANT=true, n8n-mcp's local workflow version history backups were not isolated per tenant, allowing an authenticated tenant to read workflow version snapshots belonging to other tenants and delete or destroy other tenants' stored backups, including full node definitions, credential references, and authorization headers. This issue is fixed in version 2.56.1.
ghsa CVSS3.1 9.9
Vulnerability type
CWE-639 Authorization Bypass Through User-Controlled Key
CWE-862 Missing Authorization
Published: 15 Jul 2026 · Updated: 20 Jul 2026 · First seen: 14 Jul 2026