The Loop  ·  Issue N°040

The Loop

A field journal of the AI frontier — for engineers who ship.

§ The Patch

By AI Blog Editor
Sep 17, 2026 · 32 min read

The Patch — September 17, 2026

n8n shipped three coordinated releases yesterday morning and published eight advisories ninety minutes later — and LMDeploy took four, two of them 9.8, three of which no package feed carries.

n8n cut 1.123.80, 2.40.1 and 2.39.6 inside twelve minutes yesterday morning and published eight advisories ninety minutes after that — four high, four medium. It is the only row on this table where the fix is newer than the advisory, and the only one worth interrupting your morning for. Everything else landed as backlog: LMDeploy took four advisories including two 9.8 criticals, and the newest fix among them is thirteen months old.

Component

Affected

Severity

Patched?

Action

Relevance

n8n ×8

< 2.39.6 / < 2.40.1 / < 1.123.80

8.5 · 8.1 · 7.1 ×2 (v4) + four mediums

yes → 2.39.6, yesterday

upgrade today

AI stack

lmdeploy ×4

< 0.10.2 · < 0.12.3 · < 0.15.0 · < 0.16.0

9.8 ×2 · 8.8 · 7.5

yes, but no version declared

move to 0.17.0 — it clears all four

AI stack

@zereight/mcp-gitlab

< 2.1.27

9.8 (critical)

yes → 2.1.27, Jun 22

fourth advisory in three days; 2.1.63 is current

AI stack

chromadb

≤ 1.5.9 (current)

8.1 (v3.1) · 8.6 (v4)

no — issue open since Jul 18

stop sharing one server across tenants

AI stack

rmcp ×2

< 2.0.0

8.2 · 7.5

yes → 2.0.0, Jun 29

upgrade; 3.4.0 is current

AI stack

ComfyUI

< 0.30.0

7.8 (v3.1) · 8.5 (v4)

yes → 0.30.0

upgrade; 0.36.0 is current

AI stack

vllm ×2

≤ 0.23.0 · ≤ 0.29.0 (claimed)

6.5 · 4.3 (v3.1)

one yes → 0.24.0; one no

first is closed at 0.29.0; second is availability only

AI stack

OpenTelemetry.Resources.Host

< 1.16.0-beta.2

7.0 (high)

yes → 1.16.0-beta.2

macOS build agents only

Venicecom stack

Worth your morning

n8n — a fix that is a day old, which nothing else here can say. The three releases went out at 06:43, 06:49 and 06:55 UTC on September 16 — 1.123.80 on the 1.x line, 2.40.1 on next, 2.39.6 on latest — and the advisories followed at 08:23. The four high ones are worth knowing by shape: GHSA-rx55-8qhx-4hwx (8.5) has the Dynamic Credentials authorize and revoke endpoints forwarding the caller's raw session token to a configured resolver, where registering a resolver needs only workflow:update; GHSA-89p4-6h98-c7xm (8.1) builds Public API request paths from an unencoded caller-supplied resource id; GHSA-rqch-9jrh-cr8w (7.1) lets the Supabase node's tableId reach the Auth and Storage APIs carrying the serviceRole key, which is the key that bypasses Row Level Security; and GHSA-gx6g-2hm7-c4xf (7.1) has the Wekan and Baserow credentials posting the account password to whatever host the credential's own host field names. The common factor across most of the eight is a node parameter that accepts expressions being bound to untrusted input, so the blast radius depends on which nodes your workflows expose to the outside.

Two more n8n records reached the global feed overnight from an earlier batch: CVE-2026-92587 (5.0 / 5.3 on v4, a Git-node sandbox escape past N8N_RESTRICT_FILE_ACCESS_TO) and CVE-2026-92588 (4.4 / 5.9, cross-project workflow and credential deletion through the source-control push endpoint, and only where the Environments enterprise feature is licensed and connected). Both were fixed on September 2. If you take 2.39.6 you take all ten.

LMDeploy — four advisories, two criticals, and one of them visible to your scanner. InternLM published four against lmdeploy between 02:48 and 12:34 UTC yesterday. CVE-2025-59953 (9.8) and CVE-2025-66455 (9.8) are both unsafe pickle deserialization on network-reachable ZeroMQ paths — the RPC server in one case, the DistServe P2P control plane in the other. CVE-2026-33625 (8.8) is code injection through a HuggingFace model's quantization_config.quant_dtype, and GHSA-39wr-7q6h-cf68 (7.5, no CVE) is an SSRF check that a URL can walk around.

Only the first has a global GHSA record. Query the API for the other three and it returns Not Found — they exist at repository level and nowhere else, so no pip feed carries them and no lockfile scan will raise them. All four declare no fixed version, but their ranges cap at 0.10.2, 0.12.3, 0.15.0 and 0.16.0, and current is 0.17.0 from September 2. For the quant_dtype one that is more than an inference: at tag v0.17.0 the eval() is gone, replaced by getattr(torch, quant_dtype, None) behind an isinstance(..., torch.dtype) check, so the reporter's "lmdeploy <= latest" line is stale text rather than a live claim. Upgrade to 0.17.0 and all four are behind you. The CVE years — two 2025 identifiers surfacing in September 2026, one fixed in October 2025 — are the tell that this is a queue being drained, not a bad week.

Chroma — the newest release is the affected one. CVE-2026-92782 (8.1 on v3.1, 8.6 on v4) has the Rust frontend resolving collections without validating the tenant and database segments, so an authenticated caller who knows a collection identifier can read, modify and update records in another tenant's collections while issuing requests under their own tenant path. The report has been open since July 18. chromadb 1.5.9 shipped on May 5 and is still the latest release on PyPI and the newest tag in the repository — four months, no successor. Until one arrives, tenant isolation has to come from in front of Chroma rather than from inside it: separate deployments per tenant, or an authorising proxy that pins the tenant and database on every request.

rmcp — the fix is three months old and the feed learned last night. The two advisories against the official MCP Rust SDK are CVE-2026-63127 (8.2), where the OAuth client does not validate the resource field in Protected Resource metadata and a malicious MCP server can therefore aim the flow at a legitimate authorization server and collect the token, and CVE-2026-63128 (7.5), an unauthenticated session-table leak in the Streamable HTTP server transport that never releases the allocation. Both were published to the repository on June 29 — the same day rmcp 2.0.0 went to crates.io — and reached the global advisory database at 22:13 UTC on September 16, eleven weeks later. The repository records declare no fixed version; the curated GitHub metadata supplies 2.0.0, which is the reverse of the usual arrangement and worth remembering when a repo advisory looks unpatched. Current is 3.4.0, out on September 15, and the crate is taking about 13.9 million downloads a quarter. A third from the same batch, GHSA-c9xm-49cp-xcr9 (SSRF in the OAuth client through a server-supplied resource_metadata URL, affecting ≤ 1.8.0), has no CVE and no global record at all.

Two shorter ones. CVE-2026-92816 (7.8 / 8.5 on v4) has ComfyUI failing to sanitise folder_name in its dataset save nodes, so loading a crafted workflow can write attacker-chosen content outside the output directory — the path to code execution runs through startup files, which makes an untrusted workflow a serious thing to open. Fixed in 0.30.0; current is 0.36.0 from September 15, and note the project ships from Comfy-Org/ComfyUI on GitHub rather than PyPI, where the comfyui package is an unrelated stub last touched in 2024. And vLLM appears for the third consecutive morning in two different shapes: CVE-2026-57173 (6.5) is a reviewed advisory with a real fixed version — the audio decode-duration guard was wired into /v1/audio/transcriptions but not the chat audio path, closed in 0.24.0 on June 30, so 0.29.0 clears it — while CVE-2026-92365 (4.3 / 5.3) is another vuldb-origin record claiming "up to 0.29.0" with its fix PR still unaccepted. Third day, third open PR. The contrast is the useful part: an upper bound means a fix when a release carries one, and means "where the reporter stopped" when it does not.

The one Venicecom row. CVE-2026-81192 (7.0) has the OpenTelemetry.Resources.Host NuGet package invoking sh and ioreg by bare name when it resolves the host.id attribute on macOS, so anything writable and early on PATH runs in the application's context. It has been that way since the detector was written. Fixed in 1.16.0-beta.2; the newest is 1.18.0-beta.1, and the package has never shipped a stable version, so a policy of taking only stable NuGet releases means you do not have this package at all rather than that you are stuck on a vulnerable one. Windows and Linux hosts are unaffected — this is a question for macOS build agents and developer machines.

Collection notes. The reviewed feed carried 44 entries across the window; eleven of them were djust, a Django live-view framework whose maintainers cleared a queue into 1.0.7, and thirteen more were Http4s. Neither touches the tracked stack. The unreviewed feed held 800 records for the 48-hour window, and a keyword sweep over it returned 51 hits of which six were real — the rest were Linux kernel advisories matching ray inside array, and Oracle and WordPress records matching dify inside modify. Three AI-adjacent items were read and left off the table: CVE-2026-92786 (7.8) against LightGBM through 4.7.0, an out-of-bounds write when parsing text model files, which belongs to the untrusted-model-file family rather than the LLM stack; CVE-2026-92360 (6.3) against ag-ui 1.0 with its fix PR unaccepted; and CVE-2026-90999 against Sentry Seer, carried by CERT/CC with no version data and no score. Nothing new at repository level from Ollama, llama.cpp, LangChain, LlamaIndex, Haystack, LiteLLM, Dify, Langflow, Open WebUI, CrewAI, transformers, Gradio, SGLang, Triton, the MCP reference servers or the Python and TypeScript MCP SDKs. Microsoft revised the September release document on the 16th; the revision touched Azure Linux package mirrors and nothing on the .NET, ASP.NET Core, Azure or Visual Studio entries, all of which still carry their single September 8 revision. Angular published 22.1.7 yesterday — a compiler, core and forms patch release with no security content. PrimeNG is unchanged at 22.1.1.

* * *

Thanks for reading. If a line here was useful — or plainly wrong — the comments are below and the newsletter has your back.

Elsewhere in this issue

3 more
  1. 01

    News

    Google freezes its open-source bug bounty — the AI slop finally reached a frontier lab's own vulnerability program

    Oct 5, 2026

  2. 02

    The Patch

    The Patch — October 5, 2026

    Oct 5, 2026

  3. 03

    News

    Google's Gemini tier reshuffle — free users lose Flash and Pro on October 9, and the $4.99 subscribers lose Pro four months after it was the pitch

    Oct 4, 2026

Letters

Arguments, corrections, questions. Anonymous comments allowed; be kind, be specific.