CVE-2026-41495
Last modified
CVE-2026-41495 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to version 2.47.11, when n8n-mcp runs in HTTP transport mode, incoming requests to the POST /mcp endpoint had their request metadata written to server logs regardless of the authentication outcome. EPSS estimates a 0.26% chance of exploitation in the next 30 days.
Description
n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to version 2.47.11, when n8n-mcp runs in HTTP transport mode, incoming requests to the POST /mcp endpoint had their request metadata written to server logs regardless of the authentication outcome. In deployments where logs are collected, forwarded to external systems, or viewable outside the request trust boundary (shared log storage, SIEM pipelines, support/ops access), this can result in disclosure of: bearer tokens from the Authorization header, per-tenant API keys from the, x-n8n-key header in multi-tenant setups, JSON-RPC request payloads sent to the MCP endpoint. Access control itself was not bypassed — unauthenticated requests were correctly rejected with 401 Unauthorized — but sensitive values from those rejected requests could still be persisted in logs. This issue has been patched in version 2.47.11.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| N8n-Mcp | N8n-Mcp | < 2.47.11 |
References
- https://github.com/czlonkowski/n8n-mcp/releases/tag/v2.47.11Product, Release Notes
- https://github.com/czlonkowski/n8n-mcp/security/advisories/GHSA-pfm2-2mhg-8wpxMitigation, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-41495?
How severe is CVE-2026-41495?
How do I fix CVE-2026-41495?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-41489Pi-hole is a DNS sinkhole that protects devices from unwante…8.8
- CVE-2026-4149Sonos Era 300 SMB Response Out-Of-Bounds Access Remote Code …9.8
- CVE-2026-41490Dagster is an orchestration platform for the development, pr…8.3
- CVE-2026-41491Dapr is a portable, event-driven, runtime for building distr…8.1
- CVE-2026-41492Dgraph is an open source distributed GraphQL database. Prior…9.8
- CVE-2026-41493YARD is a Ruby Documentation tool. Prior to version 0.9.42, …7.5
- CVE-2026-41496PraisonAI is a multi-agent teams system. Prior to praisonai …8.1
- CVE-2026-41497PraisonAI is a multi-agent teams system. Prior to version 4.…9.8
- CVE-2026-41498Kimai is an open-source time tracking application. Prior to …3.3
- CVE-2026-41499Wazuh is a free and open source platform used for threat pre…6.5
- CVE-2026-4150GIMP PSD File Parsing Integer Overflow Remote Code Execution…7.8
- CVE-2026-41500electerm is an open-sourced terminal/ssh/sftp/telnet/serialp…9.8
Are you affected by CVE-2026-41495?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
