GHSA-x5vx-c2c8-m3w9: n8n: AI Agents Project Viewer Privilege Escalation via run_node_tool
Summary
In n8n's AI Agents feature, a user with the Project Viewer role (read-only access) could escalate their privileges by chatting with an agent that has node tools enabled. The agent's node-execution tool didn't properly check whether the user was allowed to execute nodes or access the project's credentials (secret login information), letting Project Viewers run arbitrary tools and access secrets they shouldn't see, and potentially execute commands on the server.
Solution / Mitigation
The issue has been fixed in n8n versions 2.29.8 and 2.30.1. Users should upgrade to one of these versions or later. If upgrading is not immediately possible, administrators can temporarily disable the AI Agents module by removing `agents` from the `N8N_ENABLED_MODULES` environment variable, restrict project membership to fully trusted users only and avoid granting Project Viewer access to untrusted users on projects with agents that have node tools enabled, or disable command-execution nodes (such as Execute Command or SSH). These workarounds do not fully remediate the risk and should only be used as short-term mitigation measures.
Vulnerability Details
EPSS: 0.0%
Yes
July 22, 2026
Classification
Affected Vendors
Affected Packages
Related Issues
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
CVE-2024-27444: langchain_experimental (aka LangChain Experimental) in LangChain before 0.1.8 allows an attacker to bypass the CVE-2023-
Original source: https://github.com/advisories/GHSA-x5vx-c2c8-m3w9
First tracked: July 22, 2026 at 02:00 PM
Classified by LLM (prompt v3) · confidence: 85%