Elsas
MCP Security Status / n8n

n8n

npm package · 2 known security advisories in the elsas feed · worst severity HIGH · last seen 2026-07-22.

→ Is your version of n8n affected?
Send your dependency list or lockfile to check_affected on the MCP endpoint https://elsas.it/mcp — free when you're not affected, micro-priced (capped at $0.10) only on a confirmed match. Full remediation detail is in the paid get_today / get_items.

advisories

AdvisorySeverityCVSSAffected versionsFixed inDate
GHSA-vhf8-cg2h-cg3pMODERATE0.0>= 2.32.0, < 2.32.12.32.12026-07-22
CVE-2026-59207HIGH0.0>= 2.28.0, < 2.28.12.28.12026-07-22
These are advisories on record in the elsas feed, each linked to its primary source (GHSA/CVE/OSV/CISA-KEV) — the authoritative record. This page is informational and is not a complete audit of n8n.

verify

1. Open each linked advisory above — the primary source is the truth.
2. Each advisory was published in a daily report that is Ed25519-signed; see status.json for the report_id.
3. Full signature-verification recipe →