High severity8.8NVD Advisory· Published Jul 22, 2026· Updated Jul 28, 2026
CVE-2026-65015
CVE-2026-65015
Description
n8n versions before 2.30.1 contain a privilege escalation vulnerability in the AI Agents feature where the node-execution tool lacks proper authorization checks. A Project Viewer user can escalate privileges by chatting with an agent that has node tools enabled, executing arbitrary nodes and accessing credential secrets without proper authorization verification.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
n8nnpm | >= 2.30.0, < 2.30.1 | 2.30.1 |
n8nnpm | < 2.29.8 | 2.29.8 |
Affected products
1Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-x5vx-c2c8-m3w9ghsaADVISORY
- github.com/n8n-io/n8n/security/advisories/GHSA-x5vx-c2c8-m3w9nvdMitigationVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2026-65015ghsaADVISORY
- www.vulncheck.com/advisories/n8n-before-privilege-escalation-via-run-node-toolnvdThird Party AdvisoryVDB EntryWEB
- github.com/n8n-io/n8n/releases/tag/[email protected]ghsaWEB
- github.com/n8n-io/n8n/releases/tag/[email protected]ghsaWEB
News mentions
0No linked articles in our index yet.