CVE-2026-42282: CWE-532: Insertion of Sensitive Information into Log File in czlonkowski n8n-mcp
n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to version 2.47.13, when n8n-mcp runs in HTTP transport mode, authenticated MCP tools/call requests had their full arguments and JSON-RPC params written to server logs by the request dispatcher and several sibling code paths before any redaction. When a tool call carries credential material — most notably n8n_manage_credentials.data — the raw values can be persisted in logs. In deployments where logs are collected, forwarded to external systems, or viewable outside the request trust boundary (shared log storage, SIEM pipelines, support/ops access), this can result in disclosure of: bearer tokens and OAuth credentials sent through n8n_manage_credentials, per-tenant API keys and webhook auth headers embedded in tool arguments, arbitrary secret-bearing payloads passed to any MCP tool. The issue requires authentication (AUTH_TOKEN accepted by the server), so unauthenticated callers cannot trigger it; the runtime exposure is also reduced by an existing console-silencing layer in HTTP mode, but that layer is fragile and the values are still constructed and passed into the logger. This issue has been patched in version 2.47.13.
AI Analysis
Technical Summary
The n8n-mcp server, used to provide AI assistants access to n8n node documentation and operations, had a vulnerability (CWE-532) where sensitive credential data passed in authenticated MCP tool calls were logged in plaintext in server logs when operating in HTTP transport mode. This included bearer tokens, OAuth credentials, API keys, webhook authentication headers, and arbitrary secret payloads. The logging occurred before any redaction and despite a console-silencing layer, the sensitive data was constructed and passed to the logger. The vulnerability requires an authenticated request (valid AUTH_TOKEN) and affects versions prior to 2.47.13. The issue was patched in version 2.47.13 to prevent sensitive information leakage via logs.
Potential Impact
Sensitive credential material such as bearer tokens, OAuth credentials, API keys, and other secrets can be exposed in server logs if the vulnerable version of n8n-mcp is used in HTTP transport mode. This exposure can lead to unauthorized access if logs are collected, forwarded externally, or accessible beyond the trusted request boundary. However, exploitation requires authentication, which limits the attack surface. There is no indication of impact to integrity or availability. No known exploits in the wild have been reported.
Mitigation Recommendations
Upgrade n8n-mcp to version 2.47.13 or later, where this logging issue has been patched. Until the upgrade, restrict access to server logs to trusted personnel only and avoid running n8n-mcp in HTTP transport mode if possible. Since the vulnerability requires authentication, ensure strong authentication controls are in place. Patch status is not explicitly stated in vendor advisory fields, but the description confirms the issue is fixed in version 2.47.13.
CVE-2026-42282: CWE-532: Insertion of Sensitive Information into Log File in czlonkowski n8n-mcp
Description
n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to version 2.47.13, when n8n-mcp runs in HTTP transport mode, authenticated MCP tools/call requests had their full arguments and JSON-RPC params written to server logs by the request dispatcher and several sibling code paths before any redaction. When a tool call carries credential material — most notably n8n_manage_credentials.data — the raw values can be persisted in logs. In deployments where logs are collected, forwarded to external systems, or viewable outside the request trust boundary (shared log storage, SIEM pipelines, support/ops access), this can result in disclosure of: bearer tokens and OAuth credentials sent through n8n_manage_credentials, per-tenant API keys and webhook auth headers embedded in tool arguments, arbitrary secret-bearing payloads passed to any MCP tool. The issue requires authentication (AUTH_TOKEN accepted by the server), so unauthenticated callers cannot trigger it; the runtime exposure is also reduced by an existing console-silencing layer in HTTP mode, but that layer is fragile and the values are still constructed and passed into the logger. This issue has been patched in version 2.47.13.
CVSS v3.1
Score 4.3medium
Affected software
pkg:github/czlonkowski/n8n-mcpRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The n8n-mcp server, used to provide AI assistants access to n8n node documentation and operations, had a vulnerability (CWE-532) where sensitive credential data passed in authenticated MCP tool calls were logged in plaintext in server logs when operating in HTTP transport mode. This included bearer tokens, OAuth credentials, API keys, webhook authentication headers, and arbitrary secret payloads. The logging occurred before any redaction and despite a console-silencing layer, the sensitive data was constructed and passed to the logger. The vulnerability requires an authenticated request (valid AUTH_TOKEN) and affects versions prior to 2.47.13. The issue was patched in version 2.47.13 to prevent sensitive information leakage via logs.
Potential Impact
Sensitive credential material such as bearer tokens, OAuth credentials, API keys, and other secrets can be exposed in server logs if the vulnerable version of n8n-mcp is used in HTTP transport mode. This exposure can lead to unauthorized access if logs are collected, forwarded externally, or accessible beyond the trusted request boundary. However, exploitation requires authentication, which limits the attack surface. There is no indication of impact to integrity or availability. No known exploits in the wild have been reported.
Mitigation Recommendations
Upgrade n8n-mcp to version 2.47.13 or later, where this logging issue has been patched. Until the upgrade, restrict access to server logs to trusted personnel only and avoid running n8n-mcp in HTTP transport mode if possible. Since the vulnerability requires authentication, ensure strong authentication controls are in place. Patch status is not explicitly stated in vendor advisory fields, but the description confirms the issue is fixed in version 2.47.13.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-04-26T12:13:55.550Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 69fe3b37cbff5d86101fc04f
Added to database: 05/08/2026, 19:36:23 UTC
Last enriched: 05/16/2026, 10:02:27 UTC
Last updated: 07/31/2026, 19:22:58 UTC
Views: 114
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.