Skip to content
Vulnerability intelligence

CVE-2026-54310

n8n disclosed 11 CVEs including a CVSS 10.0 in its MCP endpoint. Flowise disclosed 6 including two RCE paths through its Custom MCP feature. The tools enterprises deploy to ‘become AI-native’ are the least secure software in the stack.

2026