๐Ÿ” CVE Alert

CVE-2026-45582

MEDIUM 6.5

n8n-MCP: Workflow telemetry sanitizer could retain partial values from URL-shaped node parameters

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.51.3, the workflow telemetry sanitizer could retain partial fragments of URL-shaped node parameters before sending workflow data to the project's anonymous telemetry backend. Values placed in HTTP-Request-style node parameters โ€” such as customer or tenant identifiers, short secrets embedded in query strings, and signed request parameters โ€” could therefore appear in stored telemetry, contrary to the collection boundary documented in PRIVACY.md. This vulnerability is fixed in 2.51.3.

CWE CWE-201
Vendor czlonkowski
Product n8n-mcp
Published May 29, 2026
Last Updated May 29, 2026
Stay Ahead of the Next One

Get instant alerts for czlonkowski n8n-mcp

Be the first to know when new medium vulnerabilities affecting czlonkowski n8n-mcp are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

czlonkowski / n8n-mcp
< 2.51.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/czlonkowski/n8n-mcp/security/advisories/GHSA-f3rg-xqjj-cj9w github.com: https://github.com/czlonkowski/n8n-mcp/pull/782 github.com: https://github.com/czlonkowski/n8n-mcp/commit/6cf6fef653fcd6d598f2f356aac4754931c7329f github.com: https://github.com/czlonkowski/n8n-mcp/releases/tag/v2.51.3