Threat · curated 22 Jul 2026

AI Agents Project Viewer Privilege Escalation via run_node_tool · Advisory · n8n-io/n8n

Coverage timeline

22 Jul 2026github.com

Single-source advisory — first reported, latest, and curated coincide.

Why it matters

The n8n AI Agents flaw shows how an agent's node-execution tool can bypass a user's role-based restrictions, letting a low-privileged user abuse the agent to run arbitrary nodes with elevated credentials and potentially achieve host command execution.

A GitHub Security Advisory (GHSA-x5vx-c2c8-m3w9) for n8n discloses a privilege-escalation flaw in its AI Agents feature: a read-only Project Viewer could chat with an agent whose node tools were enabled and, via the run_node_tool authorized only by the agent:execute scope, execute arbitrary tool nodes using the project's credentials without authorization checks. Where command- or file-capable nodes (Execute Command, SSH) are enabled, this could extend to arbitrary command execution on the n8n host. The issue is fixed in n8n versions 2.29.8 and 2.30.1.