CVE-2026-65015: n8n
High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.
n8n versions before 2.30.1 contain a privilege escalation vulnerability in the AI Agents feature where the node-execution tool lacks proper authorization checks. A Project Viewer user can escalate privileges by chatting with an agent that has node tools enabled, executing arbitrary nodes and accessing credential secrets without proper authorization verification.
Affected products
- n8n n8n: before 2.29.8 (fixed in 2.29.8); version 2.30.0 only
Published 2026-07-22. Last modified 2026-07-28.