N8N N8N — CVE-2026-54309 (Critical)
Summary
n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, when @n8n/mcp-browser is run in HTTP transport mode, the MCP endpoint accepts session initialization and tool invocation requests without any authentication. Any network-reachable client, or any website visited by the user, can establish an MCP session and invoke browser-control tools. Where the n8n AI Browser Bridge extension is installed and a browser connection is active, an unauthenticated caller can access browser-control capabilities including navigation, JavaScript evaluation, and cookie and storage access a
Why it matters
This CVE carries a CRITICAL severity rating (CVSS 10.0) in N8N N8N. Patch or mitigate promptly. EPSS percentile: 33%.
Operator check
Review CVE-2026-54309 in your asset inventory. Apply patches per vendor guidance and verify N8N is not exposed. CVSS score: 10.0. EPSS probability: 0.4%; percentile: 33%.
Sources
PatchBrief uses public sources. It does not scan environments, verify exposure, or replace vendor guidance.