CVE-2026-55608: n8n-MCP: Incorrect authorization can expose default-scope workflow version backups in multi-tenant HTTP mode
In multi-tenant HTTP mode (ENABLE_MULTI_TENANT=true), an authenticated tenant could, under certain conditions, reach n8n-mcp’s local default-scope workflow_versions backups instead of being confined to its own tenant scope. This affects n8n-mcp’s own local workflow-version storage, not a normal n8n API capability.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-55608 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →