{"data":{"id":"86cb3cd6-f6a1-4bf2-a158-ed01d32682c7","title":"GHSA-w46p-w7w2-fr9g: Duplicate Advisory:  AI Agents Project Viewer Privilege Escalation via run_node_tool","summary":"n8n (a workflow automation platform) versions before 2.30.1 have a privilege escalation vulnerability (a security flaw where a lower-level user gains higher-level access) in its AI Agents feature. A Project Viewer user with limited permissions can chat with an agent to execute arbitrary nodes (individual tasks in a workflow) and access credential secrets (sensitive authentication information) without proper authorization checks.","solution":"Update n8n to version 2.30.1 or later.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-w46p-w7w2-fr9g","publishedAt":"2026-07-22T12:32:17.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":"high","severity":"high","attackType":[],"issueType":"vulnerability","affectedPackages":["n8n@< 2.29.8"],"affectedVendors":[],"affectedVendorsRaw":["n8n"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"patchAvailable":null,"disclosureDate":"2026-07-22T12:32:17.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"agent","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null}}