Data Exposure Vulnerability in n8n-MCP by n8n
CVE-2026-42282

4.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
8 May 2026

What is CVE-2026-42282?

The n8n-MCP server, which facilitates access to node documentation and operations for AI assistants, has a significant security flaw. This vulnerability occurs when the server operates in HTTP transport mode and processes authenticated MCP tool requests. Specifically, sensitive information, such as credentials and API keys, may be logged in plaintext before any redaction occurs. As a result, these logged parameters can be viewed externally, posing a serious risk if the logs are shared or stored insecurely. Although authentication is required to exploit this vulnerability, the potential for sensitive data exposure through external logging systems makes it essential for users to upgrade to version 2.47.13, where the issue has been resolved.

Affected Version(s)

n8n-mcp < 2.47.13

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.