CyberRota Analysis
AI-GeneratedThe vulnerability affects n8n-MCP servers configured in multi-tenant HTTP mode with ENABLE_MULTI_TENANT=true, allowing authenticated tenants to access and potentially manipulate workflow version backups outside their designated scope. This could lead to unauthorized exposure or deletion of sensitive backup data from previous single-tenant deployments. Organizations using n8n-MCP prior to version 2.57.4 should prioritize updating to mitigate the risk of data leakage and integrity issues.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.57.4, multi-tenant HTTP mode with ENABLE_MULTI_TENANT=true could allow an authenticated tenant to access default-scope workflow_versions backups instead of being confined to the tenant scope, exposing or deleting workflow-version backups from prior single-tenant deployments or migrations. This issue is fixed in version 2.57.4.
Related CVEs
Other vulnerabilities affecting the same vendor(s)