Description
n8n versions before 2.30.1 contain a privilege escalation vulnerability in the AI Agents feature where the node-execution tool lacks proper authorization checks. A Project Viewer user can escalate privileges by chatting with an agent that has node tools enabled, executing arbitrary nodes and accessing credential secrets without proper authorization verification.
Published: 2026-07-22
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

n8n versions earlier than 2.30.1 have a flaw in the node‑execution tool within the AI Agents feature where authorization checks are omitted. A user with a Project Viewer role can initiate a conversation with an AI Agent that has node tools enabled and cause the tool to execute arbitrary nodes. This grants the attacker the ability to run code in the host environment and access credential secrets that are normally protected, effectively elevating privileges and exposing sensitive data.

Affected Systems

n8n, provided by n8n-io, for all installations using any version prior to 2.30.1.

Risk and Exploitability

The vulnerability has a CVSS score of 7.2, indicating medium‑to‑high severity, and an EPSS score below 1%, suggesting a low probability of exploitation. It is not listed in the CISA KEV catalog. The attack likely requires an authenticated Project Viewer to interact with an AI Agent that has node tool capabilities; once accessed, the attacker can run arbitrary nodes and read protected credentials without further verification.

Generated by OpenCVE AI on August 4, 2026 at 00:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade n8n to version 2.30.1 or later to apply the vendor‑provided fix
  • If a patch is not immediately available, disable the node‑tool feature in all AI Agents to prevent unauthorized node execution
  • Review and restrict project permissions to ensure that only users who truly need node‑tool access retain elevated roles

Generated by OpenCVE AI on August 4, 2026 at 00:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-x5vx-c2c8-m3w9 n8n: AI Agents Project Viewer Privilege Escalation via run_node_tool
History

Wed, 22 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Description n8n versions before 2.30.1 contain a privilege escalation vulnerability in the AI Agents feature where the node-execution tool lacks proper authorization checks. A Project Viewer user can escalate privileges by chatting with an agent that has node tools enabled, executing arbitrary nodes and accessing credential secrets without proper authorization verification.
Title n8n before 2.30.1 Privilege Escalation via run_node_tool
First Time appeared N8n
N8n n8n
Weaknesses CWE-863
CPEs cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*
Vendors & Products N8n
N8n n8n
References
Metrics cvssV4_0

{'score': 7.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-07-22T18:24:22.671Z

Reserved: 2026-07-21T11:32:54.897Z

Link: CVE-2026-65015

cve-icon Vulnrichment

Updated: 2026-07-22T18:20:15.319Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-22T12:18:18.587

Modified: 2026-07-28T18:17:25.740

Link: CVE-2026-65015

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T00:15:04Z

Weaknesses