CVE-2026-65015
EUVD-2026-4763122.07.2026, 12:18
n8n versions before 2.30.1 contain a privilege escalation vulnerability in the AI Agents feature where the node-execution tool lacks proper authorization checks. A Project Viewer user can escalate privileges by chatting with an agent that has node tools enabled, executing arbitrary nodes and accessing credential secrets without proper authorization verification.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| n8n | n8n | 𝑥 < 2.29.8 |
| n8n | n8n | 𝑥 < 2.29.8 |
| n8n | n8n | 2.30.0 |
| n8n | n8n | 2.30.0 |
𝑥
= Vulnerable software versions