56
/ 100
17 days ago
Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
🚨
Known vulnerabilities in dependencies: 9 critical, 23 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
🔐
You'll be asked for 5 credentials: AUTH_TOKEN, MCP_AUTH_TOKEN, N8N_API_KEY, OPENAI_API_KEY, SUPABASE_ANON_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// known CVEs in dependencies9 critical23 high1 medium22 low

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

criticaln8n@1.115.2GHSA-57g9-58c2-xjg3

n8n Has an Arbitrary File Read via Git Node

criticaln8n@1.115.2GHSA-58qr-rcgv-642v

n8n has Multiple Remote Code Execution Vulnerabilities in Merge Node AlaSQL SQL Mode

criticaln8n@1.115.2GHSA-5xrp-6693-jjx9

n8n Unsafe Workflow Expression Evaluation Allows Remote Code Execution

criticaln8n@1.115.2GHSA-62r4-hw23-cc8v

n8n Vulnerable to Arbitrary Command Execution in Pyodide based Python Code Node

criticaln8n@1.115.2GHSA-6cqr-8cfr-67f8

n8n Has Expression Escape Vulnerability Leading to RCE

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configAUTH_RATE_LIMIT_MAX
configAUTH_RATE_LIMIT_WINDOW
🔐 secretAUTH_TOKEN
configAUTH_TOKEN_FILE
configAWS_EXECUTION_ENV
configAZURE_FUNCTIONS_ENVIRONMENT
configBASE_URL
configBUILD_DB_PATH
configCORS_ORIGIN
configDISABLE_CONSOLE_OUTPUT"": "true"
configDISABLE_TELEMETRY
configENABLE_MULTI_TENANT
configFLY_APP_NAME
configGITHUB_ACTIONS
configGITHUB_REF
configGITHUB_REPOSITORY
configGITHUB_RUN_ID
configGITHUB_RUN_NUMBER
configGITHUB_SHA
configGIT_COMMIT
configGOOGLE_CLOUD_PROJECT
configHEROKU_APP_NAME
configHOST
configIS_CONTAINER
configIS_DOCKER
configKUBERNETES_SERVICE_HOST
configLOG_LEVEL"": "error",
🔐 secretMCP_AUTH_TOKEN
configMCP_MODE"": "stdio",
configMCP_PORT
configMCP_URL
configMETADATA_LIMIT
configMULTI_TENANT_SESSION_STRATEGY
🔐 secretN8N_API_KEY"": "your-api-key"
configN8N_API_URL"": "https://your-n8n-instance.com",
configN8N_CUSTOM_PATH
configN8N_MCP_CONFIG_VOLUME
configN8N_MCP_TELEMETRY_DISABLED"-e", "=true"
configN8N_MCP_USER_ID
configN8N_MODE
configN8N_MODULES_PATH
🔐 secretOPENAI_API_KEY
configOPENAI_BATCH_SIZE
configOPENAI_MODEL
configPORT
configPUBLIC_URL
configRENDER
🔐 secretSUPABASE_ANON_KEY
configSUPABASE_URL
configTELEMETRY_DISABLED
configTRUST_PROXY
configUSE_FIXED_HTTP
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 4 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/eloibiesek-n8n-mcp-1s69xb)](https://m8ven.ai/mcp/eloibiesek-n8n-mcp-1s69xb)
commit: 0f5b0d9463149923267293cd3b7255e6fb2c7116
code hash: a437b173d3923e0dabb3796297a67b9c951da8ac68b44530279304c8e53daed9
verified: 7/14/2026, 8:45:48 AM
view raw JSON →