Impact
n8n is an open source workflow automation platform that allows users to create and execute complex workflows. The identified flaw involves a missing authorization check in the Agent tool workflow factory. When a workflow that is marked as callable only by authorized parties is attached to an Agent, the check enforcing this restriction is omitted. The result is that an attacker who can build an Agent can invoke the restricted workflow and read its returned data, effectively bypassing the intended caller policy. This represents a confidential data exposure vulnerability but does not provide code execution or other higher‑level privileges.
Affected Systems
The flaw affects any deployment of n8n‑io:n8n running a version prior to 2.37.7 or 2.38.2. Those releases did not enforce the SubworkflowPolicyChecker during Agent execution. The issue was fixed in version 2.37.7 and again in 2.38.2, restoring the proper policy check for all workflow calls initiated by an Agent. Administrators should verify that no older releases are in use and review their workflow configurations for potentially sensitive data exposed through Agent tools.
Risk and Exploitability
The CVSS score of 5.3 indicates intermediate risk. EPSS information is currently unavailable, so the precise likelihood of exploitation cannot be quantified. The vulnerability is not listed in CISA’s KEV catalogue, which suggests no known widespread exploitation yet. Based on the description, it is inferred that an attacker must have permission to create or configure an Agent. If such permissions are granted to a compromised or malicious actor, the attacker could read data from any restricted workflow via the Agent, thereby breaching confidentiality. The lack of a known public exploit does not diminish the importance of addressing the flaw, particularly in environments where sensitive data is handled within workflows.
OpenCVE Enrichment
Github GHSA