GHSA-7hgx-277f-7vmg: n8n: Agent Workflow Tool Bypasses Sub-Workflow Caller Policy
Summary
n8n (a workflow automation tool) had a security gap where the '_This workflow can be called by_' access control (a setting that restricts who can run a workflow) was ignored when that workflow was used as a tool in an Agent (an AI system that can perform actions). This meant someone could use an Agent to run workflows they weren't supposed to have access to and see their results.
Solution / Mitigation
The issue has been fixed in n8n versions 2.37.7 and 2.38.2. Users should upgrade to one of these versions or later to remediate the vulnerability. If upgrading is not immediately possible, administrators should: restrict n8n instance access to fully trusted users only, audit workflows attached as Agent tools and review their caller policy settings, or remove sensitive workflows from Agent tool configurations until the instance is patched. The source notes these workarounds do not fully remediate the risk and should only be used as short-term mitigation measures.
Vulnerability Details
EPSS: 0.0%
Yes
September 8, 2026
Classification
Affected Vendors
Affected Packages
Related Issues
Original source: https://github.com/advisories/GHSA-7hgx-277f-7vmg
First tracked: September 8, 2026 at 08:01 PM
Classified by LLM (prompt v3) · confidence: 85%