CVE-2026-44694: n8n-mcp webhook and API client paths has an authenticated SSRF
Authenticated Server-Side Request Forgery affecting the webhook trigger tools, the n8n API client (N8N_API_URL), and per-request URLs supplied via the x-n8n-url header in multi-tenant HTTP mode.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-44694 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →