Vulnerability Details CVE-2026-39974
n8n-MCP is a Model Context Protocol (MCP) server that provides AI assistants with comprehensive access to n8n node documentation, properties, and operations. Prior to 2.47.4, an authenticated Server-Side Request Forgery in n8n-mcp allows a caller holding a valid AUTH_TOKEN to cause the server to issue HTTP requests to arbitrary URLs supplied through multi-tenant HTTP headers. Response bodies are reflected back through JSON-RPC, so an attacker can read the contents of any URL the server can reach — including cloud instance metadata endpoints (AWS IMDS, GCP, Azure, Alibaba, Oracle), internal network services, and any other host the server process has network access to. The primary at-risk deployments are multi-tenant HTTP installations where more than one operator can present a valid AUTH_TOKEN, or where a token is shared with less-trusted clients. Single-tenant stdio deployments and HTTP deployments without multi-tenant headers are not affected. This vulnerability is fixed in 2.47.4.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 2.1%
CVSS Severity
CVSS v3 Score 8.5
Products affected by CVE-2026-39974
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.10.1
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.10.2
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.10.3
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.10.4
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.10.5
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.10.6
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.10.7
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.10.8
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.10.9
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.11.0
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.11.1
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.11.2
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.11.3
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.12.0
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.12.1
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.12.2
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.13.0
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.13.1
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.13.2
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.14.0
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.14.1
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.14.2
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.14.3
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.14.4
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.14.5
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.14.6
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.14.7
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.15.0
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.15.1
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.15.2
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.15.3
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.15.4
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.15.5
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.15.6
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.16.0
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.16.1
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.16.2
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.16.3
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.17.0
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.17.1
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.17.2
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.17.3
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.17.5
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.17.6
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.18.0
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.18.1
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.18.10
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.18.3
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.18.4
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.18.5
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.18.6
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.18.7
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.18.8
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.18.9
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.19.0
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.19.1
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.19.2
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.19.3
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.19.4
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.19.5
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.19.6
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.20.0
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.20.1
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.20.2
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.20.3
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.20.4
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.20.5
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.20.6
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.20.7
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.20.8
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.21.0
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.21.1
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.22.10
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.22.11
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.22.12
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.22.13
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.22.14
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.22.15
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.22.16
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.22.17
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.22.18
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.22.19
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.22.20
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.22.21
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.22.6
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.22.7
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.22.8
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.22.9
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.23.0
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.24.0
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.24.1
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.26.0
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.26.1
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.26.2
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.26.3
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.26.4
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.26.5
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.27.0
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.27.1
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.27.2
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.28.0
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.28.1
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.28.2
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.28.3
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.28.4
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.28.6
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.28.7
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.28.8
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.28.9
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.29.0
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.29.2
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.29.3
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.29.4
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.29.5
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.30.0
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.30.1
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.30.2
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.31.0
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.31.1
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.31.2
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.31.3
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.31.4
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.31.5
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.31.6
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.31.7
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.31.8
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.31.9
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.32.0
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.32.1
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.33.0
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.33.1
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.33.2
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.33.3
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.33.4
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.33.5
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.33.6
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.34.0
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.34.1
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.34.2
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.34.3
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.34.4
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.34.5
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.35.0
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.35.1
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.35.2
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.35.3
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.35.4
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.35.5
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.35.6
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.36.0
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.36.1
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.36.2
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.37.1
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.37.2
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.37.3
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.37.4
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.38.0
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.40.0
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.40.1
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.40.2
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.40.3
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.40.4
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.40.5
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.41.0
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.41.1
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.41.2
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.41.3
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.41.4
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.42.0
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.42.1
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.42.2
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.42.3
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.43.0
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.44.0
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.44.1
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.45.0
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.45.1
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.46.0
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.46.1
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.47.0
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.47.1
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.47.2
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.47.3
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.7.9
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.8.1
-
cpe:2.3:a:n8n-mcp:n8n-mcp:2.9.1