n8n fixes a batch of high-severity flaws, including SQL injection, code execution and an approval bypass: update to 2.42.1 or 2.41.4
EditorialBy TrustList Editorial
n8n published ten security advisories on 30 September 2026, eight rated high, for its workflow-automation platform: SQL injection, code execution in the Git node, an HMAC bypass on waiting executions and owner account takeover. Update to 2.42.1 or 2.41.4.
- Cybersecurity
- Vulnerability Management
- Patch Management
- Workflow Management
- +1 more
About n8n fixes a batch of high-severity flaws, including SQL injection, code execution and an approval bypass: update to 2.42.1 or 2.41.4
n8n fixes a batch of high-severity flaws, including SQL injection, code execution and an approval bypass: update to 2.42.1 or 2.41.4
2 October 2026 — n8n, the workflow-automation platform that many companies run on their own servers to connect business systems and AI agents, published ten security advisories on its code repository on 30 September 2026. Eight are rated high and two moderate. Italy's national CSIRT issued an alert on 1 October listing eleven high-severity CVEs in n8n, and the Canadian Centre for Cyber Security published an advisory the same day.
The flaws
Among the advisories of 30 September:
- SQL injection in the Microsoft SQL node through expression interpolation into the query field.
- Code execution in the Git node's log operation through repository configuration that is not neutralised.
- Send-and-wait HMAC bypass: someone holding an execution's resume token can approve a waiting step without proper authorisation, so a workflow can run on under its owner's credentials. n8n rates it 7.0 and fixes it in 2.42.1 and 2.41.4.
- Owner account takeover through shared-prototype mutation in the MCP workflow-validation interpreter.
- Unauthenticated, unbounded OAuth client persistence through the authorize endpoint.
- A shared-workflow credential check that misses nested and inline sub-workflows, so credentials can be reached in ways the sharing model did not intend.
- Stored cross-site scripting in the Chat Trigger's hosted chat page and in the binary-data file preview.
The Italian alert gives the affected ranges for the CVEs it lists as versions before 1.123.80, 2.0.0 to 2.39.5, and 2.40.0. Each GitHub advisory names its own patched versions.
Not yet independently verified. The patched versions are confirmed here for one advisory (the HMAC bypass: 2.42.1 and 2.41.4); the other advisories were read from n8n’s list, which does not show the versions. n8n’s advisories carry no CVE numbers yet, so we have not matched them one by one to the CVEs in the Italian alert. We will update this when it can be confirmed, and remove this note.
What to do
- Update self-hosted n8n to 2.42.1 or 2.41.4 (or later) on the 2.x line. If you are still on 1.x, take the newest 1.123 release and plan the move to 2.x.
- Open each advisory that matches a node you use (Microsoft SQL, Git, Chat Trigger, send-and-wait, MCP tools) and check its fixed version against yours.
- Review who can create, edit and share workflows: several flaws need an authenticated user, so a large editor group widens the risk.
- Rotate credentials stored in n8n if your instance is exposed to the internet and was unpatched, and review recent executions for approvals nobody made.
- On n8n Cloud, ask whether your instance has been updated.
Why it matters
Workflow-automation servers hold credentials for the systems they connect: CRM, finance, email, databases and now AI agents. A flaw that lets one user reach another's credentials, or run code on the server, exposes all of them at once.
Sources
- n8n security advisories (GitHub), including GHSA-728h-pmr2-7cgh — 30 September 2026
- CSIRT Italia (ACN): Rilevate vulnerabilità in n8n (AL07/261001/CSIRT-ITA) — 1 October 2026
- Canadian Centre for Cyber Security: n8n security advisory (AV26-985) — 1 October 2026
Categories & features
- Cybersecurity
- Vulnerability Management
- Patch Management
- Workflow Management
- Automation
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More CybersecurityThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.