Threat · curated 22 Jul 2026
AI Agents Project Viewer Privilege Escalation via run_node_tool · Advisory · n8n-io/n8n
First reported github.com
Coverage timeline
Single-source advisory — first reported, latest, and curated coincide.
Why it matters
The n8n AI Agents flaw shows how an agent's node-execution tool can bypass a user's role-based restrictions, letting a low-privileged user abuse the agent to run arbitrary nodes with elevated credentials and potentially achieve host command execution.
A GitHub Security Advisory (GHSA-x5vx-c2c8-m3w9) for n8n discloses a privilege-escalation flaw in its AI Agents feature: a read-only Project Viewer could chat with an agent whose node tools were enabled and, via the run_node_tool authorized only by the agent:execute scope, execute arbitrary tool nodes using the project's credentials without authorization checks. Where command- or file-capable nodes (Execute Command, SSH) are enabled, this could extend to arbitrary command execution on the n8n host. The issue is fixed in n8n versions 2.29.8 and 2.30.1.