n8n (30 Sep GHSA batch): MCP read→owner takeover, Git-node RCE, MSSQL injection, Send-and-Wait HMAC bypass — patch 2.42.1 / 2.41.4 (+1.123.83 Git)
n8n GitHub security advisories published 30 September 2026 (High; CVSS 4.0 vectors on GHSA pages; no CVE IDs assigned on these GHSAs at publish). Lead issues: GHSA-5jr4-xmvf-frmj — MCP workflow-validation interpreter allows shared prototype mutation so a member with only a read grant can pass permission checks and take over the instance owner account (MFA-protected accounts not affected); GHSA-x8wx-g24x-3549 — Git node Log operation skipped local-config neutralization, enabling program execution as the n8n process user (also usable as an agent tool; also patched on 1.123.83); GHSA-5qpp-pqww-h7fp — Microsoft SQL node v1 interpolates expressions into Query without parameterisation (arbitrary SQL under stored DB credential when untrusted input is bound); GHSA-728h-pmr2-7cgh — Send-and-Wait waiting-webhook HMAC bypass lets a caller with a resume token approve another party’s waiting execution (downstream runs as workflow owner); GHSA-3qcw-p65v-c7vq — unauthenticated unbounded OAuth client persistence via authorize endpoint (disk-fill). Same-day batch also includes additional High/Moderate items (credential check gaps, Chat Trigger XSS, AI Workflow Builder prototype pollution, etc.). Distinct from desk n8n-ai-agents-authz-20260914 (CVE-2026-65015 / CVE-2026-59207 AI Agents authz, Sep 14). Primary: n8n GitHub security advisories 30 Sep.
- Product
- n8n (self-hosted / cloud workflow automation; MCP server; Microsoft SQL node; Git node; Send-and-Wait)
- Versions
- Affected (batch lead issues): n8n < 2.42.1 and < 2.41.4 (both trains need the matching patched build). Git node also: < 1.123.83. Fixed: 2.42.1+, 2.41.4+; Git additionally 1.123.83+. Confirm lockfile/image tags resolve to patched builds.
- CVSS
- High (CVSS 4.0; GHSA — numeric score not published on advisory API)
- Exploited in Australia?
- unknown
- Patch to
- Upgrade n8n to 2.42.1+ or 2.41.4+ immediately (1.x Git-node users: 1.123.83+). Until patched: disable instance-level MCP server if unused; enable MFA on owner accounts; restrict instance network access to trusted operators; audit Microsoft SQL / Git / Send-and-Wait workflows that bind untrusted webhook/HTTP input or gate high-consequence approvals; avoid Git node Log against attacker-controlled repo configs.
Primary: n8n GHSA-5jr4-xmvf-frmj — MCP prototype mutation → owner takeover (High; 30 Sep 2026) · Vendor: n8n — GitHub security advisories index · CVE: CVE-2026-65015, CVE-2026-59207 · n8n GHSA-x8wx-g24x-3549 — Git node Log operation code execution (High; 30 Sep 2026)
