GHSA-w46p-w7w2-fr9g: Duplicate Advisory: AI Agents Project Viewer Privilege Escalation via run_node_tool
highvulnerability
security
Source: GitHub Advisory DatabaseJuly 22, 2026
Summary
n8n (a workflow automation platform) versions before 2.30.1 have a privilege escalation vulnerability (a security flaw where a lower-level user gains higher-level access) in its AI Agents feature. A Project Viewer user with limited permissions can chat with an agent to execute arbitrary nodes (individual tasks in a workflow) and access credential secrets (sensitive authentication information) without proper authorization checks.
Solution / Mitigation
Update n8n to version 2.30.1 or later.
Classification
Attack SophisticationModerate
Impact (CIA+S)
confidentialityintegrity
AI Component TargetedAgent
Affected Vendors
Affected Packages
n8n@< 2.29.8
Monthly digest — independent AI security research
Original source: https://github.com/advisories/GHSA-w46p-w7w2-fr9g
First tracked: July 22, 2026 at 02:00 PM
Classified by LLM (prompt v3) · confidence: 85%