Description
n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the workflow setting named This workflow can be called by was enforced by the Execute Workflow node but not when a workflow was attached to an Agent as a tool. A user able to build an Agent could invoke a restricted workflow and read its returned data. The affected path is packages/cli/src/modules/agents/tools/workflow-tool-factory.ts, where executeWorkflow omitted SubworkflowPolicyChecker.checkForProject. This issue is fixed in versions 2.37.7 and 2.38.2.
Published: 2026-09-08
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authorization bypass enabling unauthorized data access
Action: Patch immediately
AI Analysis

Impact

n8n is an open source workflow automation platform that allows users to create and execute complex workflows. The identified flaw involves a missing authorization check in the Agent tool workflow factory. When a workflow that is marked as callable only by authorized parties is attached to an Agent, the check enforcing this restriction is omitted. The result is that an attacker who can build an Agent can invoke the restricted workflow and read its returned data, effectively bypassing the intended caller policy. This represents a confidential data exposure vulnerability but does not provide code execution or other higher‑level privileges.

Affected Systems

The flaw affects any deployment of n8n‑io:n8n running a version prior to 2.37.7 or 2.38.2. Those releases did not enforce the SubworkflowPolicyChecker during Agent execution. The issue was fixed in version 2.37.7 and again in 2.38.2, restoring the proper policy check for all workflow calls initiated by an Agent. Administrators should verify that no older releases are in use and review their workflow configurations for potentially sensitive data exposed through Agent tools.

Risk and Exploitability

The CVSS score of 5.3 indicates intermediate risk. EPSS information is currently unavailable, so the precise likelihood of exploitation cannot be quantified. The vulnerability is not listed in CISA’s KEV catalogue, which suggests no known widespread exploitation yet. Based on the description, it is inferred that an attacker must have permission to create or configure an Agent. If such permissions are granted to a compromised or malicious actor, the attacker could read data from any restricted workflow via the Agent, thereby breaching confidentiality. The lack of a known public exploit does not diminish the importance of addressing the flaw, particularly in environments where sensitive data is handled within workflows.

Generated by OpenCVE AI on September 9, 2026 at 08:55 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade n8n to version 2.37.7 or later (2.38.2 is also patched).
  • Restrict permissions for creating Agents to trusted users until the patch is deployed, or temporarily disable the Agent tool if possible.
  • Audit existing workflows for caller policy settings and apply additional safeguards such as access control lists to sensitive data streams.

Generated by OpenCVE AI on September 9, 2026 at 08:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-7hgx-277f-7vmg n8n: Agent Workflow Tool Bypasses Sub-Workflow Caller Policy
History

Thu, 10 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared N8n
N8n n8n
CPEs cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*
Vendors & Products N8n
N8n n8n
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Wed, 09 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the workflow setting named This workflow can be called by was enforced by the Execute Workflow node but not when a workflow was attached to an Agent as a tool. A user able to build an Agent could invoke a restricted workflow and read its returned data. The affected path is packages/cli/src/modules/agents/tools/workflow-tool-factory.ts, where executeWorkflow omitted SubworkflowPolicyChecker.checkForProject. This issue is fixed in versions 2.37.7 and 2.38.2.
Title n8n: Agent Workflow Tool Bypasses Sub-Workflow Caller Policy
Weaknesses CWE-862
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-09T13:52:43.147Z

Reserved: 2026-09-08T16:44:23.781Z

Link: CVE-2026-86996

cve-icon Vulnrichment

Updated: 2026-09-09T13:52:33.059Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T22:19:18.240

Modified: 2026-09-10T20:54:58.743

Link: CVE-2026-86996

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T13:15:14Z

Weaknesses