Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-f3rg-xqjj-cj9w | n8n-MCP: Workflow telemetry sanitizer could retain partial values from URL-shaped node parameters |
Mon, 01 Jun 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
N8n-mcp
N8n-mcp n8n-mcp |
|
| CPEs | cpe:2.3:a:n8n-mcp:n8n-mcp:*:*:*:*:*:*:*:* | |
| Vendors & Products |
N8n-mcp
N8n-mcp n8n-mcp |
Fri, 29 May 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 29 May 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Czlonkowski
Czlonkowski n8n-mcp |
|
| Vendors & Products |
Czlonkowski
Czlonkowski n8n-mcp |
Fri, 29 May 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.51.3, the workflow telemetry sanitizer could retain partial fragments of URL-shaped node parameters before sending workflow data to the project's anonymous telemetry backend. Values placed in HTTP-Request-style node parameters — such as customer or tenant identifiers, short secrets embedded in query strings, and signed request parameters — could therefore appear in stored telemetry, contrary to the collection boundary documented in PRIVACY.md. This vulnerability is fixed in 2.51.3. | |
| Title | n8n-MCP: Workflow telemetry sanitizer could retain partial values from URL-shaped node parameters | |
| Weaknesses | CWE-201 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-29T18:44:55.077Z
Reserved: 2026-05-12T19:00:14.601Z
Link: CVE-2026-45582
Updated: 2026-05-29T18:44:42.478Z
Status : Analyzed
Published: 2026-05-29T14:16:30.563
Modified: 2026-06-01T18:41:02.210
Link: CVE-2026-45582
No data.
OpenCVE Enrichment
Updated: 2026-05-29T15:15:46Z
Github GHSA