PT-2026-50175 · Unknown+1 · @N8N/Mcp-Browser+1

·

CVE-2026-54309

·

Published

2026-06-16

·

Updated

2026-07-16

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions n8n versions prior to 2.25.7 n8n versions prior to 2.26.2
Description When @n8n/mcp-browser is operated in HTTP transport mode using the --transport http flag, the MCP endpoint allows session initialization and tool invocation requests without authentication. This enables any network-reachable client or website visited by the user to establish a session and utilize browser-control tools. If the n8n AI Browser Bridge extension is installed and a connection is active, an unauthenticated caller can perform actions such as navigation, JavaScript evaluation, and access cookies and storage within the user's actual browser profile.
Recommendations Update to version 2.25.7 or later. Update to version 2.26.2 or later. Avoid running @n8n/mcp-browser with the HTTP transport and use the default stdio transport instead. Restrict network access to the listening port to trusted clients only using host-based firewall rules if HTTP transport is required.

Exploit

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54309
GHSA-QRX8-25QR-5R7V

Affected Products

@N8N/Mcp-Browser
N8N