Improper access control in n8n - CVE-2026-54309
Published: June 16, 2026
n8n
Detailed vulnerability description
The vulnerability allows a remote attacker to access browser-control capabilities and disclose sensitive information.
The vulnerability exists due to improper access control in the MCP HTTP transport endpoint when handling session initialization and tool invocation requests. A remote attacker can send crafted requests to access browser-control capabilities and disclose sensitive information.
Only instances running @n8n/mcp-browser with the HTTP transport enabled are affected. If the n8n AI Browser Bridge extension is installed and a browser connection is active, the issue can expose navigation, JavaScript evaluation, and access to browser cookies and storage in the user's real browser profile.