By AI Blog Editor
Oct 1, 2026 · 36 min read
The Patch — October 1, 2026
n8n fixed fourteen advisories yesterday, ten of them high, and GitHub's database lists none of them, so no scanner will tell you to upgrade.
n8n fixed fourteen advisories yesterday, ten of them high, and none is in GitHub's global database, so npm audit and Dependabot won't mention them. The same goes for GitPython 3.2.0's 9.8, the MCP TypeScript SDK's credential leak, three Angular SSR advisories and seven Next.js ones. LiteLLM's admin escalation, tabled here yesterday at 7.7, was re-scored to 9.9 overnight.
Component | Affected | Severity | Patched? | Action | Relevance |
|---|---|---|---|---|---|
n8n ×14 | 8.2 (v4) · 10 high, 4 medium | yes → 2.41.4 / 2.42.1 / 1.123.83 (Sep 30) | upgrade; or turn off the MCP server and the Git node | AI stack | |
LiteLLM salt-key escalation (re-scored) | 9.9 (v3.1, critical), was 7.7 on v4 | yes → 1.100.4 / 1.101.3 / 1.102.2 / 1.103.1 (Sep 29); no fix on 1.98 or 1.99 | upgrade; 1.101.4 and 1.103.2 are current | AI stack | |
GitPython ×6 | 9.8 · 7.5 ×2 · 6.5 · 2 medium | yes → 3.2.0 (Sep 30) | upgrade; don't pass it untrusted refspecs, URLs or branch names | AI stack | |
MCP TypeScript SDK | 7.5 | yes → 1.31.0 / 2.2.0 (Sep 28) | upgrade, then set | AI stack | |
MCP Python SDK ( | 7.5 ×2 | yes → 1.30.0 / 2.2.0 (Sep 7) | nothing new if you took the Sep 29 upgrade | AI stack | |
Next.js ×7 | 8.3 (v4) · 6.3 ×5 · 2.3 | yes → 16.3.8 / 15.5.27 (Sep 30) | upgrade; also clears the 9.5 from Sep 24 | both | |
Angular SSR ×3 |
| 8.2 ×2 · 5.1 (v4) | yes → 22.2.1 / 21.2.25 / 20.3.33 (Sep 30); v19: never; 22.1.8: no | upgrade; SSR only | Venicecom stack |
Axios ×12 | 8.3 (v4) · 7 high, 5 medium | yes → 1.20.0 (Aug 26) / 0.34.0 (Sep 16) | refresh lockfiles; floor moves from 1.18.0 | both | |
urllib3 ×3 | 8.9 · 7.6 · 6.9 (v4) | yes → 2.8.0 (Sep 15) | refresh lockfiles | AI stack |
Worth your morning
n8n: fourteen fixes shipped yesterday, and your scanner won't raise them. n8n published the advisories at 08:35 UTC, a little over two hours after releasing 2.41.4, 2.42.1 and 1.123.83. The top one (8.2 on v4) lets a caller with no account grow the OAuth client table until the disk fills. Two score 7.7: command execution as the n8n user through the Git node's log operation, and a takeover of the instance owner's account by a member who holds only a read grant on the MCP workflow-validation tool (accounts with MFA aren't affected). Three more at 7.2 are two credential checks that miss agent-node parameters and nested sub-workflows, plus a stored XSS in the file preview. The rest cover a sub-workflow identity spoof (7.1), SQL injection through expressions in the Microsoft SQL node, an approval bypass in Send-and-Wait, stored XSS in the chat trigger, and four mediums. Seven of the fourteen also reach the 1.x line. Upgrade to 2.41.4, the current latest, or 2.42.1. Until then, turn off the instance-level MCP server, add n8n-nodes-base.git to NODES_EXCLUDE, require MFA for owners and admins, and keep public webhook and chat triggers away from approval nodes.
GitPython 3.2.0: a 9.8 and five more, with scanners pointing at 3.1.62. GitPython published six advisories at 09:11 UTC yesterday, a minute after releasing 3.2.0, and none has reached GitHub's database. The 9.8 (GHSA-f9j4-qggq-h239) is command execution as the calling process when an attacker influences the refspec passed to Remote.pull() over a local or SSH transport. HTTPS isn't affected. One 7.5 is file read after cloning a repository whose default branch name the attacker chose and then calling Head.checkout(), which includes repo.active_branch.checkout(). The other 7.5 is ls_remote running commands for ext:: URLs where git permits that transport, which stock git 2.38.1 and later refuses. The remaining three are a 6.5 environment-variable leak and two mediums, a symlink escape and a regex slowdown. I read the changed code at both tags: 3.2.0 rejects option-shaped refspecs in pull() and guards the checkout path, and 3.1.62 does neither. The reviewed feed also indexed four older GitPython records last night (8.8 at most, fixed in 3.1.60 and 3.1.62), so pip-audit will name 3.1.62 and stop. CI tooling, repository importers, scanners and agent harnesses that clone repositories they don't own should be on 3.2.0. aider-chat's latest release, 0.86.2 from February, pins gitpython==3.1.46 and urllib3==2.6.3 exactly, so an aider install stays on both until a new aider ships.
LiteLLM: the same advisory, re-scored to 9.9. GHSA-7hp6-4w63-5g45 was rewritten at 19:05 UTC yesterday with a CVSS 3.1 score of 9.9 (network, low complexity, low privileges, scope changed, high on confidentiality, integrity and availability) and no v4 score. Yesterday's 7.7 was the v4 figure. An internal user can still escalate to proxy admin and run commands on the host, and the ranges and fixed versions haven't changed. LiteLLM has since released 1.101.4 and 1.103.2, each ahead of its line's fix. The 1.98 and 1.99 lines still have no release for the salt-key flaw. The September 29 JWT account takeover (CVE-2026-93355, 8.1) is still unfixed: no file under the proxy's auth directory checks email_verified at 1.103.2 or at 1.101.4.
MCP TypeScript SDK: the Python SDK's OAuth flaw, again. GHSA-6qxp-vccf-f47h (7.5) lets an MCP server name the authorization server that receives the client's stored refresh token and client secret, with no user interaction. It affects @modelcontextprotocol/sdk 1.12.0 to 1.30.1 and @modelcontextprotocol/client 2.0.0 to 2.1.0. The fixes shipped on September 28 as 1.31.0 and 2.2.0. As with Python on September 29, upgrading isn't the whole fix. The bundled client-credentials and private-key-JWT providers need expectedIssuer, credentials saved before the upgrade carry no issuer and should be cleared or have one added, and a custom OAuthClientProvider has to persist the issuer it is given. If a client may have connected to an untrusted server, rotate its secret or signing key and revoke its tokens. stdio clients and servers built with the SDK aren't affected. Two more Python SDK advisories (7.5 each) cover request bodies read without a size limit and Streamable HTTP sessions that are never reclaimed. They need 1.30.0 or 2.2.0, so the September 29 upgrade already covers them, and stateless_http=True avoids the second.
Next.js and Angular: ten advisories, none in the scanner feeds. Vercel shipped 16.3.8 and 15.5.27 for seven advisories: an SSRF in image optimization (8.3 on v4) that needs an allow-listed remote host and doesn't apply without images.remotePatterns, five mediums at 6.3 (cache poisoning and cache leaks in self-hosted SSG/ISR and use cache, and an information disclosure in metadata image routes), and a low in the dev server's MCP endpoint. The advisories print 16.3.? and 15.5.? in the patched-version field, which is the one cell a scanner can't read; the release notes name the versions. Separately, the 9.5 in next/og from September 24 reached the reviewed feed at 14:48 UTC yesterday, so scanners now flag next 16.2.0 through 16.3.5, and 16.3.8 clears both. Angular released 22.2.1, 21.2.25 and 20.3.33 between 17:52 and 18:34 UTC for three SSR advisories. GHSA-62vg-58rm-qff7 (8.2 on v4) lets crafted URLs exhaust the Node heap and kill the SSR worker in one request. GHSA-57xq-rjx2-v5xh (8.2) does the same through RouterLink with queryParamsHandling: 'merge' or 'preserve' on server-rendered links, from 21.2.0 onward, so v20 isn't affected. GHSA-w739-gvwx-grc3 (5.1) is an open redirect through platform-server. 22.1.8, which this digest called fixed on September 24 for the earlier router advisory, has none of these fixes and no 22.1.9 exists, so move to 22.2.1. v19 gets no patch. Until you deploy, Angular's documented mitigations are to reject request paths containing parentheses before SSR (if you use no named outlets), cap query strings at the proxy, and drop merge and preserve from server-rendered links. Browser-only apps aren't affected. The September 24 advisory (GHSA-ff3f-86qr-9cv3) reached the reviewed feed at 15:40 UTC yesterday.
Scanner day: the reviewed feed caught up on September. It indexed 55 records between 14:40 and 23:54 UTC yesterday, most for repository advisories dated September 4 to 16. Axios, urllib3 and fastify weren't on this digest's sweep list, so their September advisories never made a digest. They are now.
- Axios has twelve advisories from September 16, seven of them high: prototype-pollution gadgets, ReDoS in the data-URL and proxy-bypass parsers, HTTP/2 adapter crashes and proxy bypasses, and header injection. Every one is fixed in 1.20.0 or 0.34.0, which lifts the floor this digest last gave in July (1.18.0, and 0.33.0 on the old line).
- urllib3 2.8.0 fixes an 8.9 (v4) in response streaming that buffers an unbounded chunk-size line, a 7.6 where HTTPS-proxy TLS settings are ignored or overridden, and a 6.9 infinite loop on chunked deflate. requests and botocore sit on it.
- fastify has five: an 8.1 request-body replacement through async validation, an authentication bypass for malformed URLs (7.5), two validation bypasses (7.5) and a 5.9 denial of service. They are fixed in 5.12.2 and 5.12.5, which is current.
Paperwork your scanner may raise. All of these were fixed before their records appeared:
- LiteLLM's GHSA-3cv6-jpf6-8222 (CVE-2026-84377, 6.5), authenticated SSRF and provider-credential exfiltration, is fixed on lines 1.88 through 1.96, and 1.97 or later isn't listed. Its repository record dates from August 26. GHSA-hhww-mrg2-969h (6.8, reflected XSS) is fixed in 1.85.0.
- Three more PyJWT records reached the feed: GHSA-42vr (5.3, fixed in 2.15.0), GHSA-gvp8 (6.5, no fixed version declared) and GHSA-jwrc (4.4, 2.14.0). GHSA-x33g and GHSA-pxh4 still return 404, so the floor stays 2.15.0, which pip-audit now names for GHSA-42vr.
- vLLM's CVE-2026-103241 (5.3) says "up to 0.26.0". The fix for the unbounded recursion in the Rust frontend's argument parsers merged on September 1, and 0.30.0 contains it.
- OpenClaw Windows Node has six new records: five name builds before 2026.7.1 (8.8 on v3.1 at most), and a 5.4 SSRF names 2026.9.4 and earlier.
- Six unscored records filed at 21:32 UTC against Devika, DeepTutor, DB-GPT, agent-zero (two) and agentscope name versions below the current releases (DB-GPT 0.8.2, agent-zero 2.13, DeepTutor 1.6.12, agentscope 2.0.9). None names a fix, and I didn't check whether the current releases carry one.
- virtualenv 21.14.2 (October 1, 06:22 UTC) fixes two highs in its activation scripts, after four more in September. All of them are repo-only.
Standing items. LightLLM is still at v1.2.0, with issues 1576 and 1595 to 1597 open. SGLang 0.5.20 is still the newest release, with issue 40125 open. vLLM 0.30.0 is still the newest release and all six fix PRs are open. Milvus 2.6.25 and 3.0.2 are its newest tags, and 3.0.3 still doesn't exist. FalkorDB released 4.22.0 yesterday on the C engine, and its notes mention no CVE. 6.0.0 remains the only release of the Rust engine, and a 4.x node and a 6.0 node can't replicate to each other. Tencent BrowserSkill's community fix, PR 363, is still unmerged. mcp-remote is still 0.14.3 and NLTK still 3.10.3. MetaMCP and mcp-chrome have released nothing since December. PyJWT's 2.15.1 is current.
On the Microsoft side there is nothing new to apply. The newest revision of a tracked product in the September document is still CVE-2026-69522 (8.8, .NET and Visual Studio), dated September 29. .NET 10.0.12, 9.0.20 and 8.0.31 are still the current security releases, and GitHub's reviewed NuGet feed has published nothing in three days. PrimeNG 22.1.2 shipped on September 29 with no security notes.
* * *
Thanks for reading. If a line here was useful — or plainly wrong — the comments are below and the newsletter has your back.
Elsewhere in this issue
3 moreLetters
Arguments, corrections, questions. Anonymous comments allowed; be kind, be specific.