{"id":3620,"date":"2026-06-01T21:00:48","date_gmt":"2026-06-01T21:00:48","guid":{"rendered":"https:\/\/www.ucartz.com\/updates\/n8n-mcp-information-disclosure-vulnerability-cve-2026-45582-medium-severity\/"},"modified":"2026-06-01T21:00:48","modified_gmt":"2026-06-01T21:00:48","slug":"n8n-mcp-information-disclosure-vulnerability-cve-2026-45582-medium-severity","status":"publish","type":"post","link":"https:\/\/www.ucartz.com\/updates\/n8n-mcp-information-disclosure-vulnerability-cve-2026-45582-medium-severity\/","title":{"rendered":"n8n-MCP Information Disclosure Vulnerability (CVE-2026-45582) \u2014 Medium Severity"},"content":{"rendered":"<h2>Understanding the n8n-MCP Information Leak<\/h2>\n<p>n8n-MCP is a server designed to help AI assistants access documentation, properties, and operations for n8n nodes. Recently, a vulnerability was discovered in older versions of n8n-MCP that could unintentionally expose sensitive information.<\/p>\n<p>Before version 2.51.3, the system responsible for sanitizing workflow data before sending it to the project&#8217;s anonymous telemetry backend had a flaw. This flaw meant that parts of URLs, specifically the path and query string sections, were not properly removed. As a result, sensitive data like customer or tenant identifiers, short secrets found in query strings, and signed request parameters could inadvertently be included in the stored telemetry data. This was contrary to the privacy policies that were supposed to prevent such collection.<\/p>\n<h2>CVE Details<\/h2>\n<ul>\n<li><strong>Product:<\/strong> n8n-MCP<\/li>\n<li><strong>Published Date:<\/strong> May 29, 2026<\/li>\n<li><strong>Severity:<\/strong> Medium (CVSS Score: 6.5)<\/li>\n<li><strong>Status:<\/strong> Analyzed<\/li>\n<\/ul>\n<h2>Affected Products<\/h2>\n<p>This information disclosure vulnerability affects all versions of n8n-MCP prior to <strong>2.51.3<\/strong>. If you are running an older version, your system might be at risk of inadvertently logging sensitive data.<\/p>\n<h2>Current Status<\/h2>\n<p>The vulnerability, identified as CVE-2026-45582, has been thoroughly analyzed. Developers have acknowledged the issue and have released a patch to address it, ensuring that sensitive URL components are properly redacted before telemetry data is transmitted.<\/p>\n<h2>Severity Level<\/h2>\n<p>The Common Vulnerability Scoring System (CVSS) rates this vulnerability with a score of 6.5, classifying it as &#8216;Medium&#8217; severity. While not allowing direct control over the system, successful exploitation could lead to unauthorized disclosure of potentially sensitive user or system data through telemetry logs. This could have privacy implications and potentially be misused if intercepted.<\/p>\n<h2>Possible Solutions<\/h2>\n<p>The good news is that a fix is readily available. To protect your n8n-MCP installation from this information disclosure vulnerability, it is crucial to update to version <strong>2.51.3<\/strong> or later as soon as possible.<\/p>\n<p>The fix implemented in version 2.51.3 ensures that:<\/p>\n<ul>\n<li>A component called `sanitizeObject` now completely redacts URL-named fields, changing their values to `[REDACTED_URL]` to prevent any part of the URL from leaking.<\/li>\n<li>Previous logic that only hid the hostname in `sanitizeString` has been removed, ensuring a more comprehensive redaction.<\/li>\n<li>Additional defense-in-depth measures have been added to `event-validator.ts` by using a strict schema for nodes, which rejects any unexpected top-level keys in node data, further preventing unintended data exposure.<\/li>\n<\/ul>\n<p>By upgrading, you ensure that your workflow telemetry is sanitized correctly, adhering to privacy standards and protecting sensitive information.<\/p>\n<h2>References<\/h2>\n<p>https:\/\/github.com\/czlonkowski\/n8n-mcp\/commit\/6cf6fef653fcd6d598f2f356aac4754931c7329f<\/p>\n<p>https:\/\/github.com\/czlonkowski\/n8n-mcp\/pull\/782<\/p>\n<p>https:\/\/github.com\/czlonkowski\/n8n-mcp\/releases\/tag\/v2.51.3<\/p>\n<p>https:\/\/github.com\/czlonkowski\/n8n-mcp\/security\/advisories\/GHSA-f3rg-xqjj-cj9w<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Understanding the n8n-MCP Information Leak n8n-MCP is a server designed to help AI assistants access documentation, properties, and operations for n8n nodes. Recently, a vulnerability was discovered in older versions of n8n-MCP that could unintentionally expose sensitive information. Before version 2.51.3, the system responsible for sanitizing workflow data before sending it to the project&#8217;s anonymous [&hellip;]<\/p>\n","protected":false},"author":17,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[800,697,1083,765,1115],"class_list":["post-3620","post","type-post","status-publish","format-standard","hentry","category-security","tag-data-privacy","tag-information-disclosure","tag-n8n-mcp","tag-security-update","tag-telemetry"],"blocksy_meta":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>n8n-MCP Information Disclosure Vulnerability (CVE-2026-45582) \u2014 Medium Severity - Web Hosting and IT Consultancy Services<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.ucartz.com\/updates\/n8n-mcp-information-disclosure-vulnerability-cve-2026-45582-medium-severity\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"n8n-MCP Information Disclosure Vulnerability (CVE-2026-45582) \u2014 Medium Severity - Web Hosting and IT Consultancy Services\" \/>\n<meta property=\"og:description\" content=\"Understanding the n8n-MCP Information Leak n8n-MCP is a server designed to help AI assistants access documentation, properties, and operations for n8n nodes. Recently, a vulnerability was discovered in older versions of n8n-MCP that could unintentionally expose sensitive information. Before version 2.51.3, the system responsible for sanitizing workflow data before sending it to the project&#8217;s anonymous [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.ucartz.com\/updates\/n8n-mcp-information-disclosure-vulnerability-cve-2026-45582-medium-severity\/\" \/>\n<meta property=\"og:site_name\" content=\"Web Hosting and IT Consultancy Services\" \/>\n<meta property=\"article:published_time\" content=\"2026-06-01T21:00:48+00:00\" \/>\n<meta name=\"author\" content=\"Alex Joseph\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Alex Joseph\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/n8n-mcp-information-disclosure-vulnerability-cve-2026-45582-medium-severity\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/n8n-mcp-information-disclosure-vulnerability-cve-2026-45582-medium-severity\\\/\"},\"author\":{\"name\":\"Alex Joseph\",\"@id\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/#\\\/schema\\\/person\\\/1ba9bfab02a76dee216c9f55bb634e56\"},\"headline\":\"n8n-MCP Information Disclosure Vulnerability (CVE-2026-45582) \u2014 Medium Severity\",\"datePublished\":\"2026-06-01T21:00:48+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/n8n-mcp-information-disclosure-vulnerability-cve-2026-45582-medium-severity\\\/\"},\"wordCount\":451,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/#organization\"},\"keywords\":[\"Data Privacy\",\"Information Disclosure\",\"N8n Mcp\",\"Security Update\",\"Telemetry\"],\"articleSection\":[\"Security\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/n8n-mcp-information-disclosure-vulnerability-cve-2026-45582-medium-severity\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/n8n-mcp-information-disclosure-vulnerability-cve-2026-45582-medium-severity\\\/\",\"url\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/n8n-mcp-information-disclosure-vulnerability-cve-2026-45582-medium-severity\\\/\",\"name\":\"n8n-MCP Information Disclosure Vulnerability (CVE-2026-45582) \u2014 Medium Severity - Web Hosting and IT Consultancy Services\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/#website\"},\"datePublished\":\"2026-06-01T21:00:48+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/n8n-mcp-information-disclosure-vulnerability-cve-2026-45582-medium-severity\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/n8n-mcp-information-disclosure-vulnerability-cve-2026-45582-medium-severity\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/n8n-mcp-information-disclosure-vulnerability-cve-2026-45582-medium-severity\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"n8n-MCP Information Disclosure Vulnerability (CVE-2026-45582) \u2014 Medium Severity\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/#website\",\"url\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/\",\"name\":\"Web Hosting and IT Consultancy Services\",\"description\":\"Discover the Potential of Digital Transformation through Effortless Hosting and Professional IT Consulting!\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/#organization\",\"name\":\"Web Hosting and IT Consultancy Services\",\"url\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/wp-content\\\/uploads\\\/2025\\\/12\\\/ucartzLogo-1.png\",\"contentUrl\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/wp-content\\\/uploads\\\/2025\\\/12\\\/ucartzLogo-1.png\",\"width\":165,\"height\":50,\"caption\":\"Web Hosting and IT Consultancy Services\"},\"image\":{\"@id\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/#\\\/schema\\\/person\\\/1ba9bfab02a76dee216c9f55bb634e56\",\"name\":\"Alex Joseph\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/0969fa5fefa2739cbd6fd5eaf04fed619e19f40d42e4a42650090606944ff747?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/0969fa5fefa2739cbd6fd5eaf04fed619e19f40d42e4a42650090606944ff747?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/0969fa5fefa2739cbd6fd5eaf04fed619e19f40d42e4a42650090606944ff747?s=96&d=mm&r=g\",\"caption\":\"Alex Joseph\"},\"description\":\"Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.\",\"url\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/author\\\/alexjoseph\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"n8n-MCP Information Disclosure Vulnerability (CVE-2026-45582) \u2014 Medium Severity - Web Hosting and IT Consultancy Services","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.ucartz.com\/updates\/n8n-mcp-information-disclosure-vulnerability-cve-2026-45582-medium-severity\/","og_locale":"en_US","og_type":"article","og_title":"n8n-MCP Information Disclosure Vulnerability (CVE-2026-45582) \u2014 Medium Severity - Web Hosting and IT Consultancy Services","og_description":"Understanding the n8n-MCP Information Leak n8n-MCP is a server designed to help AI assistants access documentation, properties, and operations for n8n nodes. Recently, a vulnerability was discovered in older versions of n8n-MCP that could unintentionally expose sensitive information. Before version 2.51.3, the system responsible for sanitizing workflow data before sending it to the project&#8217;s anonymous [&hellip;]","og_url":"https:\/\/www.ucartz.com\/updates\/n8n-mcp-information-disclosure-vulnerability-cve-2026-45582-medium-severity\/","og_site_name":"Web Hosting and IT Consultancy Services","article_published_time":"2026-06-01T21:00:48+00:00","author":"Alex Joseph","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Alex Joseph","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.ucartz.com\/updates\/n8n-mcp-information-disclosure-vulnerability-cve-2026-45582-medium-severity\/#article","isPartOf":{"@id":"https:\/\/www.ucartz.com\/updates\/n8n-mcp-information-disclosure-vulnerability-cve-2026-45582-medium-severity\/"},"author":{"name":"Alex Joseph","@id":"https:\/\/www.ucartz.com\/updates\/#\/schema\/person\/1ba9bfab02a76dee216c9f55bb634e56"},"headline":"n8n-MCP Information Disclosure Vulnerability (CVE-2026-45582) \u2014 Medium Severity","datePublished":"2026-06-01T21:00:48+00:00","mainEntityOfPage":{"@id":"https:\/\/www.ucartz.com\/updates\/n8n-mcp-information-disclosure-vulnerability-cve-2026-45582-medium-severity\/"},"wordCount":451,"commentCount":0,"publisher":{"@id":"https:\/\/www.ucartz.com\/updates\/#organization"},"keywords":["Data Privacy","Information Disclosure","N8n Mcp","Security Update","Telemetry"],"articleSection":["Security"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.ucartz.com\/updates\/n8n-mcp-information-disclosure-vulnerability-cve-2026-45582-medium-severity\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.ucartz.com\/updates\/n8n-mcp-information-disclosure-vulnerability-cve-2026-45582-medium-severity\/","url":"https:\/\/www.ucartz.com\/updates\/n8n-mcp-information-disclosure-vulnerability-cve-2026-45582-medium-severity\/","name":"n8n-MCP Information Disclosure Vulnerability (CVE-2026-45582) \u2014 Medium Severity - Web Hosting and IT Consultancy Services","isPartOf":{"@id":"https:\/\/www.ucartz.com\/updates\/#website"},"datePublished":"2026-06-01T21:00:48+00:00","breadcrumb":{"@id":"https:\/\/www.ucartz.com\/updates\/n8n-mcp-information-disclosure-vulnerability-cve-2026-45582-medium-severity\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.ucartz.com\/updates\/n8n-mcp-information-disclosure-vulnerability-cve-2026-45582-medium-severity\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.ucartz.com\/updates\/n8n-mcp-information-disclosure-vulnerability-cve-2026-45582-medium-severity\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.ucartz.com\/updates\/"},{"@type":"ListItem","position":2,"name":"n8n-MCP Information Disclosure Vulnerability (CVE-2026-45582) \u2014 Medium Severity"}]},{"@type":"WebSite","@id":"https:\/\/www.ucartz.com\/updates\/#website","url":"https:\/\/www.ucartz.com\/updates\/","name":"Web Hosting and IT Consultancy Services","description":"Discover the Potential of Digital Transformation through Effortless Hosting and Professional IT Consulting!","publisher":{"@id":"https:\/\/www.ucartz.com\/updates\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.ucartz.com\/updates\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.ucartz.com\/updates\/#organization","name":"Web Hosting and IT Consultancy Services","url":"https:\/\/www.ucartz.com\/updates\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.ucartz.com\/updates\/#\/schema\/logo\/image\/","url":"https:\/\/www.ucartz.com\/updates\/wp-content\/uploads\/2025\/12\/ucartzLogo-1.png","contentUrl":"https:\/\/www.ucartz.com\/updates\/wp-content\/uploads\/2025\/12\/ucartzLogo-1.png","width":165,"height":50,"caption":"Web Hosting and IT Consultancy Services"},"image":{"@id":"https:\/\/www.ucartz.com\/updates\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.ucartz.com\/updates\/#\/schema\/person\/1ba9bfab02a76dee216c9f55bb634e56","name":"Alex Joseph","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/0969fa5fefa2739cbd6fd5eaf04fed619e19f40d42e4a42650090606944ff747?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/0969fa5fefa2739cbd6fd5eaf04fed619e19f40d42e4a42650090606944ff747?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/0969fa5fefa2739cbd6fd5eaf04fed619e19f40d42e4a42650090606944ff747?s=96&d=mm&r=g","caption":"Alex Joseph"},"description":"Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.","url":"https:\/\/www.ucartz.com\/updates\/author\/alexjoseph\/"}]}},"_links":{"self":[{"href":"https:\/\/www.ucartz.com\/updates\/wp-json\/wp\/v2\/posts\/3620","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.ucartz.com\/updates\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.ucartz.com\/updates\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.ucartz.com\/updates\/wp-json\/wp\/v2\/users\/17"}],"replies":[{"embeddable":true,"href":"https:\/\/www.ucartz.com\/updates\/wp-json\/wp\/v2\/comments?post=3620"}],"version-history":[{"count":0,"href":"https:\/\/www.ucartz.com\/updates\/wp-json\/wp\/v2\/posts\/3620\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.ucartz.com\/updates\/wp-json\/wp\/v2\/media?parent=3620"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.ucartz.com\/updates\/wp-json\/wp\/v2\/categories?post=3620"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.ucartz.com\/updates\/wp-json\/wp\/v2\/tags?post=3620"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}