CVE-2026-54309

n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, when @n8n/mcp-browser is run in HTTP transport mode, the MCP endpoint accepts session initialization and tool invocation requests without any authentication. Any network-reachable client, or any website visited by the user, can establish an MCP session and invoke browser-control tools. Where the n8n AI Browser Bridge extension is installed and a browser connection is active, an unauthenticated caller can access browser-control capabilities including navigation, JavaScript evaluation, and cookie and storage access against the user's real browser profile. This issue only affects instances where @n8n/mcp-browser is run with the HTTP transport (--transport http). This vulnerability is fixed in 2.25.7 and 2.26.2.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*
cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*

History

25 Jun 2026, 18:40

Type Values Removed Values Added
CPE cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*
First Time N8n
N8n n8n
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 10.0
References () https://github.com/n8n-io/n8n/security/advisories/GHSA-qrx8-25qr-5r7v - () https://github.com/n8n-io/n8n/security/advisories/GHSA-qrx8-25qr-5r7v - Mitigation, Vendor Advisory

23 Jun 2026, 16:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-23 16:17

Updated : 2026-06-25 18:40


NVD link : CVE-2026-54309

Mitre link : CVE-2026-54309

CVE.ORG link : CVE-2026-54309


JSON object : View

Products Affected

n8n

  • n8n
CWE
CWE-306

Missing Authentication for Critical Function