Today's shape locked at 18:00 with three coordinated-disclosure batches — Gitea, n8n, Netty — and two new CISA KEV entries. Late escalation at 21:00 ET: a fourth wave landed within 75 minutes of that synthesis, adding 50 more GHSA advisories across six projects before the day was done.
n8n absorbed a second batch on top of this morning's eleven — 24 more items including a full Git-node remote-code-execution variant (crafted repo hooks running as the n8n process user), an expression-sandbox escape reaching system commands through arrow-function bodies, and three separate unparameterized-SQL-injection bugs across its MySQL, Postgres Trigger, and Snowflake nodes. Next.js, Eclipse Jetty, JupyterLab, and LiteLLM each had their first appearance of the day: Jetty's Digest authentication silently accepts a substituted password for any non-Latin-1 credential, JupyterLab's image viewer can escalate a crafted image into server-side code execution, and LiteLLM's MCP auth handler falls back to an authenticated session object on key-validation failure — letting an unauthenticated caller reach any configured MCP tool.
→ Operational priority for the night none of the 50 late items clears GHSA's critical bar and CISA added nothing new to KEV, so Friday's SharePoint and Check Point deadlines are still the top priority — but treat tonight's wave as equal-weight to this afternoon's batch, not an afterthought, and patch the LiteLLM MCP auth bypass and the second n8n Git-node RCE first, since both need only a fabricated header or a crafted local repo to reach unauthenticated-adjacent impact.