mediumVulnerability

CVE-2026-86996

## Impact A workflow's "_This workflow can be called by_" setting was enforced by the Execute Workflow node but was not consulted when the same workflow was attached to an Agent as a tool. A user who could build an Agent could therefore call a workflow that its owner had restricted, and read back what it returned. The patch applies the sub-workflow caller policy on the Agent tool path. ## Patches The issue has been fixed in n8n versions 2.37.7 and 2.38.2. Users should upgrade to one of these versions or later to remediate the vulnerability. ## Workarounds If upgrading is not immediately possible, administrators should consider the following temporary mitigations: - Restrict n8n instance access to fully trusted users only. - Audit workflows attached as Agent tools and review their caller policy settings. - Remove sensitive workflows from Agent tool configurations until the instance is patched. These workarounds do not fully remediate the risk and should only be used as short-term mitigation measures.

Properties

ghsa_id
GHSA-7hgx-277f-7vmg
severity
medium
summary
n8n: Agent Workflow Tool Bypasses Sub-Workflow Caller Policy
cve_id
CVE-2026-86996
is_ghsa_only
false
ghsa_published
2026-09-08T21:33:47Z
source_url
https://github.com/advisories/GHSA-7hgx-277f-7vmg
ghsa_updated
2026-09-08T21:33:48Z

Related Entities (4)

VULNERABLE_TO (1)

[Software]npm/n8n

AFFECTS (1)

[Software]npm/n8n

HAS_WEAKNESS (1)

[Weakness]Missing Authorization

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-86996 — Ninja Signal Threat Intelligence | Ninja Signal