osfeed.dev
Release / / with v2.41.4, v2.42.0, v2.42.1, v2.42.2, v2.42.3, v2.43.0, v2.44.0, v2.44.1, v2.45.0, v2.45.1, v2.46.0, v2.46.1, v2.47.0

n8n-MCP v2.47.1

Audit an n8n instance for exposed secrets and workflow security issues.

Before you upgrade to v2.47.1

1 to fix

Send Bearer authentication to GET /sse and `POST` /messages; SSE uses these dedicated endpoints. StreamableHTTP remains at `POST` /mcp.

Action requiredConnect an MCP client to node documentation and optional n8n management tools.Affects: Legacy SSE clients and unauthenticated SSE configurations
Read the evidence

What changed in v2.47.1

Audit an n8n instance for exposed secrets and workflow security issues.

Available through npm or Docker at v2.47.1. Instance management requires configured n8n API access.

New things you can do

Audit an n8n instance and scan workflows for hardcoded secrets, unauthenticated webhooks and error-handling gaps.

AddedAudit an n8n instance and scan workflows for hardcoded secrets, unauthenticated webhooks and error-handling gaps.
Read the evidence

Create, inspect, update and delete credentials and retrieve credential schemas.

AddedCreate, inspect, update and delete credentials and retrieve credential schemas.
Read the evidence

Request workflow proposals from natural-language descriptions and review them before deployment.

AddedRequest workflow proposals from natural-language descriptions and review them before deployment.
Read the evidence

Fixed and improved

Full workflow updates preserve existing credential references when the supplied nodes omit them.

Now worksCreate, inspect, edit and delete workflows on an n8n instance.
Read the evidence

Pattern search exposes common node combinations and connection chains from templates.

ImprovedFind workflow templates by task, nodes or metadata and retrieve their workflow JSON.
Read the evidence

`search_nodes` can return resource-grouped operation trees with `includeOperations`.

ImprovedFind n8n nodes, their settings, operations, documentation and example configurations.
Read the evidence

Seeded by @iluxav with Codex, from the release's public sources. Each change links to its evidence.

Share

LinkedIn takes the link and its card only; write your text there.

X LinkedIn Reddit Hacker News Bluesky