Impact
n8n versions earlier than 2.30.1 have a flaw in the node‑execution tool within the AI Agents feature where authorization checks are omitted. A user with a Project Viewer role can initiate a conversation with an AI Agent that has node tools enabled and cause the tool to execute arbitrary nodes. This grants the attacker the ability to run code in the host environment and access credential secrets that are normally protected, effectively elevating privileges and exposing sensitive data.
Affected Systems
n8n, provided by n8n-io, for all installations using any version prior to 2.30.1.
Risk and Exploitability
The vulnerability has a CVSS score of 7.2, indicating medium‑to‑high severity, and an EPSS score below 1%, suggesting a low probability of exploitation. It is not listed in the CISA KEV catalog. The attack likely requires an authenticated Project Viewer to interact with an AI Agent that has node tool capabilities; once accessed, the attacker can run arbitrary nodes and read protected credentials without further verification.
OpenCVE Enrichment
Github GHSA