Status: UPDATED | Advisory ID: CVE-2026-39974
| CVE | CVE-2026-39974 |
| CVSS Score / Version | 8.5 (High) / CVSS v3.1 |
| Updated | 2026-06-17 |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N |
| CVSS Prose | attack vector is network; attack complexity is low; privileges required is low; user interaction is none; scope is changed; confidentiality impact is high; integrity impact is low; availability impact is none. |
| Affected products | n8n-mcp n8n-mcp |
| Classified as | CWE-918 (Server-Side Request Forgery (SSRF)) |
| Vendor | Product | Affected Versions | Patch Status |
|---|---|---|---|
| n8n-mcp | n8n-mcp |
| Subsystems | General OT |
| Sectors | Multiple |
n8n-MCP is a Model Context Protocol (MCP) server that provides AI assistants with comprehensive access to n8n node documentation, properties, and operations. Prior to 2.47.4, an authenticated Server-Side Request Forgery in n8n-mcp allows a caller holding a valid AUTH_TOKEN to cause the server to issue HTTP requests to arbitrary URLs supplied through multi-tenant HTTP headers. Response bodies are reflected back through JSON-RPC, so an attacker can read the contents of any URL the server can reach — including cloud instance metadata endpoints (AWS IMDS, GCP, Azure, Alibaba, Oracle), internal network services, and any other host the server process has network access to. The primary at-risk deployments are multi-tenant HTTP installations where more than one operator can present a valid AUTH_TOKEN, or where a token is shared with less-trusted clients. Single-tenant stdio deployments and HTTP deployments without multi-tenant headers are not affected. This vulnerability is fixed in 2.47.4. (NVD)
Monitor n8n-mcp's web page for any future patch releases. See vendor advisory link below.