{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/n8n-version-2.30.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"id":"CVE-2026-65015"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["n8n (All versions prior to 2.29.8)","n8n (Version 2.30.0)"],"_cs_severities":["high"],"_cs_tags":["n8n","privilege-escalation","vulnerability","ai-agents","web-application"],"_cs_type":"advisory","_cs_vendors":["n8n GmbH"],"content_html":"\u003cp\u003eA high-severity privilege escalation vulnerability, tracked as CVE-2026-65015, has been identified in n8n's AI Agents feature. This flaw allows an authenticated user with a read-only Project Viewer role to bypass intended access controls and execute arbitrary tool nodes, thereby gaining access to credential secrets they are not authorized to view. The vulnerability stems from the \u003ccode\u003enode-execution\u003c/code\u003e tool within the AI Agent, which fails to properly verify user permissions when executing nodes or accessing project credentials, relying only on the broad \u003ccode\u003eagent:execute\u003c/code\u003e scope. This issue impacts organizations using the AI Agents feature and sharing team projects with lower-privileged members, significantly increasing the risk of unauthorized data access and, in configurations with command-capable nodes, potential arbitrary command execution on the underlying n8n host system. Patches have been released in versions 2.29.8 and 2.30.1.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker, authenticated as a Project Viewer, gains access to an n8n team project that has an AI Agent configured with 'node tools' enabled.\u003c/li\u003e\n\u003cli\u003eThe attacker interacts with the AI Agent through the chat interface, crafting an input that specifically triggers the \u003ccode\u003erun_node_tool\u003c/code\u003e function.\u003c/li\u003e\n\u003cli\u003eThe AI Agent's \u003ccode\u003enode-execution\u003c/code\u003e tool receives the request to execute a node, initiated by the Project Viewer.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003enode-execution\u003c/code\u003e tool proceeds to execute the requested node using the project's configured credentials.\u003c/li\u003e\n\u003cli\u003eCrucially, the \u003ccode\u003enode-execution\u003c/code\u003e tool's authorization mechanism relies solely on the \u003ccode\u003eagent:execute\u003c/code\u003e scope and fails to verify that the requesting Project Viewer has the necessary permissions to execute nodes or access the specific credentials involved.\u003c/li\u003e\n\u003cli\u003eThis bypass allows the Project Viewer to execute arbitrary tool nodes beyond their assigned read-only privileges, effectively escalating their capabilities within the n8n environment.\u003c/li\u003e\n\u003cli\u003eThe Project Viewer can now access and utilize sensitive credential secrets stored within the project, which they were previously unauthorized to read, facilitating further internal reconnaissance or lateral movement.\u003c/li\u003e\n\u003cli\u003eIf the n8n instance has command- or file-capable tool nodes (such as 'Execute Command' or 'SSH') enabled, the Project Viewer can leverage this escalated privilege to achieve arbitrary command execution on the n8n host system, leading to full system compromise.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability (CVE-2026-65015) in n8n's AI Agents feature allows a read-only Project Viewer to escalate their privileges within the n8n environment. This leads to unauthorized execution of arbitrary tool nodes and access to sensitive credential secrets, enabling the attacker to perform actions explicitly denied by their role. For instances where command- or file-capable tool nodes (e.g., 'Execute Command', 'SSH') are enabled, this privilege escalation can be leveraged for arbitrary command execution on the n8n host. This directly impacts organizations using n8n with AI Agents and team projects, risking data exfiltration, system compromise, and unauthorized manipulation of workflows by lower-privileged users. All users of the AI Agents feature who share team projects are potentially affected.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade n8n instances immediately to version 2.29.8 or 2.30.1, or later, to remediate CVE-2026-65015.\u003c/li\u003e\n\u003cli\u003eIf immediate upgrade is not possible, consider disabling the AI Agents module by removing \u003ccode\u003eagents\u003c/code\u003e from the \u003ccode\u003eN8N_ENABLED_MODULES\u003c/code\u003e environment variable as a temporary mitigation for CVE-2026-65015.\u003c/li\u003e\n\u003cli\u003eRestrict project membership to fully trusted users only and avoid granting Project Viewer access to untrusted users on projects containing agents with node tools enabled.\u003c/li\u003e\n\u003cli\u003eDisable command-execution nodes (e.g., \u003ccode\u003eExecute Command\u003c/code\u003e, \u003ccode\u003eSSH\u003c/code\u003e) within n8n workflows if they have been re-enabled, to limit the potential impact of arbitrary command execution from successful exploitation.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rule in this brief to your SIEM to detect suspicious process creation activities that may indicate successful arbitrary command execution on Linux hosts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-22T18:05:27Z","date_published":"2026-07-22T18:05:27Z","id":"https://feed.craftedsignal.io/briefs/2026-07-n8n-ai-agents-privilege-escalation/","summary":"A privilege escalation vulnerability (CVE-2026-65015) exists in n8n's AI Agents feature, allowing users with the read-only Project Viewer role to execute arbitrary tool nodes and access unauthorized credential secrets, potentially leading to arbitrary command execution on the n8n host.","title":"n8n AI Agents Privilege Escalation via run_node_tool","url":"https://feed.craftedsignal.io/briefs/2026-07-n8n-ai-agents-privilege-escalation/"}],"language":"en","title":"CraftedSignal Threat Feed - N8n (Version 2.30.0)","version":"https://jsonfeed.org/version/1.1"}