Summary
n8n-MCP: Incorrect authorization can expose default-scope workflow version backups in multi-tenant HTTP mode
Advisory details
Summary
In multi-tenant HTTP mode (ENABLE_MULTI_TENANT=true), an authenticated tenant could, under certain conditions, reach n8n-mcp's local default-scope workflow_versions backups instead of being confined to its own tenant scope. This affects n8n-mcp's own local workflow-version storage, not a normal n8n API capability.
Impact
An authenticated MCP HTTP tenant could read or delete workflow-version backups stored in the default (single-tenant) scope — for example backups left from a prior single-tenant deployment or a migration period. Workflow snapshots may contain sensitive workflow configuration depending on their contents. Single-tenant and stdio deployments are not affected.
Affected versions
<= 2.57.3
Patched version
2.57.4
Remediation
Upgrade to n8n-mcp 2.57.4 or later. The fix requires a complete tenant context in multi-tenant mode and fails closed for workflow-version access that cannot be attributed to a specific tenant.
Workarounds
- Restrict network access to the HTTP endpoint (firewall / reverse proxy / VPN) so only trusted callers can reach it.
- Run in stdio mode, which has no multi-tenant HTTP surface.
- If default-scope backups from a prior single-tenant deployment are not needed, removing them eliminates the exposure.
Credit
Reported by @DavidCarliez.
References
Related vulnerabilities
All Supply chain →- HIGHCVE-2026-55485
piccolo-admin has a privilege escalation issue - admin to superuser via session-token disclosure in GET /api/tables/sessions/.
- MEDIUMGHSA-mf8r-wm2w-f8c5#phpmyfaq/phpmyfaq
phpMyFAQ public FAQ APIs expose inactive FAQ content
- MEDIUMGHSA-mf8r-wm2w-f8c5#thorsten/phpmyfaq
phpMyFAQ public FAQ APIs expose inactive FAQ content
- MEDIUMCVE-2026-71433
LangGraph: Namespace prefix matching crosses segment boundaries in Postgres and SQLite stores
- MEDIUMCVE-2026-57897
Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs
- MEDIUMCVE-2026-58427
Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145