n8n patches 13 flaws, up to owner account takeover
Several bugs need no login at all, others allow running programs or taking over accounts. Fixed in versions 1.123.83, 2.41.4 and 2.42.1.
n8n released versions 1.123.83, 2.41.4 and 2.42.1 on 29 September 2026, closing 13 security vulnerabilities. CERT-Bund at the BSI (Germany's Federal Office for Information Security) rates the set as high risk overall. The most severe flaw, with a CVSS score of 8.2, sits in the OAuth endpoint: an attacker without a login can create unlimited client records there, which never expire, until the disk fills up. Also without a login, the webhook resolver let anyone trigger workflows in other projects, which then ran with that project's credentials.
Several other flaws require an account on the instance. A member can use the log operation of the Git node to run arbitrary programs with the permissions of the n8n process. Anyone holding only a read grant on the MCP server can take over the instance owner's account, unless it is protected by multi-factor authentication. Version 1 of the Microsoft SQL node, by contrast, is open to outside attack as soon as a workflow passes external input into its Query field, because it inserts expressions there into the SQL text without parameterisation.
Why it matters: An n8n instance holds the credentials for every system connected to it, and two of the flaws let editors of shared workflows use the owner's credentials. Anyone running n8n themselves should update to one of the three versions, since n8n itself calls the listed workarounds incomplete. Three of the advisories concern n8n's own AI agents; teams not using them can switch off the Agents module via N8N_ENABLED_MODULES.
Discussion
I read every comment before it appears.No comments yet. Yours would be the first.