Fetching from the wire…
Public story · 2026-08-04 · high
Version 2.34.0 also tightens editor postMessage origins and blocks stray GET calls on n8n's MCP endpoint, per the release notes.
Why now: The fix is new in n8n's 2.34.0 release notes, and n8n hasn't published how many nested-agent workflows ran exposed before it landed.
n8n shipped version 2.34.0, fixing a bug that let sub-agent tool calls bypass the human-approval gate a parent workflow had set, per GitHub's release notes.
The project already carries more agentic-AI security advisories than any other in the category. A hole in how approval propagates through nested agents lands on a platform where builders already chain real automation.
When a workflow nested another agent inside it, the approval step wasn't propagating down. The sub-agent could call tools the top-level workflow never cleared.
This release also adds a configurable origin allowlist for the editor's postMessage handling, per the release notes. That closes off a path for untrusted pages to reach the n8n interface. It also fixes the instance's MCP endpoint, returning a 405 on GET requests instead of processing them.
If you're running approval-gated workflows in n8n with any sub-agent calls, don't assume anything before 2.34.0 enforced what you configured. Update to 2.34.0 and check every workflow where an agent calls another agent.
n8n's advisory lead in this category is a byproduct of how many builders route real agent chains through it. It's not proof the code is weaker than competitors'. That holds up only if the next nested-agent bug doesn't look like this one.
Each link below shares sources, entities, or timing with this story.
3,364 stars since its August 17 creation. Every action against a computer, file, MCP server or UI component routes through a single gateway that resolves the target, decides it against policy, writes an audit row, then acts or refuses while naming the rule. Each bot gets its o...
every-app/open-seo took +517 stars today on a base of 14,882, offering keyword research, backlinks, rank tracking and site audits. The model is bring-your-own DataForSEO API key and pay per call instead of a $100+/month subscription, with a $10/month hosted option. It exposes...
Waishnav/devspace (4,247 stars, v1.0.8 August 25) runs a local Node server exposing read, edit, search and shell execution over MCP, reached through a reverse proxy tunnel like Cloudflare or ngrok, with password-gated owner approval per client. The pitch is turning ChatGPT int...
Frontier labs publish demos. This one published the thing they actually page. Anthropic's August 18 writeup describes Claude Tag running as the first responder for CI failures inside the company. Dedicated service account. MCP connectors to Datadog, Grafana, PagerDuty, GitHub...
affaan-m/ECC (36.3k forks, MIT) bundles 67 agents, 284 skills, 94 legacy command shims, and "instincts", patterns learned from prior sessions with confidence scores that auto-recall when relevant, plus a .ecc/memory/ markdown vault that's explicitly cross-harness, so context s...
Every story above generates tokens, and tokens are money. rtk is the clearest "do this today" item in the whole dataset. It's a single Rust binary, 59,658 stars, created January 22 and pushed as recently as June 7, that proxies common dev commands and claims 60 to 90% reductio...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.