High severityNVD Advisory· Published Jul 22, 2026· Updated Jul 22, 2026
n8n before 2.30.1 Privilege Escalation via run_node_tool
CVE-2026-65015
Description
n8n versions before 2.30.1 contain a privilege escalation vulnerability in the AI Agents feature where the node-execution tool lacks proper authorization checks. A Project Viewer user can escalate privileges by chatting with an agent that has node tools enabled, executing arbitrary nodes and accessing credential secrets without proper authorization verification.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
n8nnpm | >= 2.30.0, < 2.30.1 | 2.30.1 |
n8nnpm | < 2.29.8 | 2.29.8 |
Affected products
1Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-x5vx-c2c8-m3w9ghsaADVISORY
- github.com/n8n-io/n8n/security/advisories/GHSA-x5vx-c2c8-m3w9ghsavendor-advisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2026-65015ghsaADVISORY
- www.vulncheck.com/advisories/n8n-before-privilege-escalation-via-run-node-toolghsathird-party-advisoryWEB
- github.com/n8n-io/n8n/releases/tag/[email protected]ghsaWEB
- github.com/n8n-io/n8n/releases/tag/[email protected]ghsaWEB
News mentions
0No linked articles in our index yet.