
[CVE-2026-39974: HIGH] n8n-MCP server had a severe Server-Side Request Forgery vulnerability up to version 2.47.4, allowing attackers with valid AUTH_TOKEN to trigger HTTP requests to any URL via multi-tenan...#cve,CVE-2026-39974,#cybersecurity https://cvefind.com/CVE-2026-39974
Post summary
The post announces CVE-2026-39974, a severe SSRF vulnerability in n8n-MCP servers up to version 2.47.4 that allows attackers with a valid AUTH_TOKEN to send arbitrary HTTP requests. No PoC, exploit code, patch, or active exploitation details are provided.

