highVulnerability

GHSA-w46p-w7w2-fr9g

## Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-x5vx-c2c8-m3w9. This link is maintained to preserve external references. ## Original Description n8n versions before 2.30.1 contain a privilege escalation vulnerability in the AI Agents feature where the node-execution tool lacks proper authorization checks. A Project Viewer user can escalate privileges by chatting with an agent that has node tools enabled, executing arbitrary nodes and accessing credential secrets without proper authorization verification.

Properties

ghsa_id
GHSA-w46p-w7w2-fr9g
summary
Duplicate Advisory: AI Agents Project Viewer Privilege Escalation via run_node_tool
severity
high
cve_id
GHSA-w46p-w7w2-fr9g
is_ghsa_only
true
ghsa_published
2026-07-22T12:32:17Z
source_url
https://github.com/advisories/GHSA-w46p-w7w2-fr9g
ghsa_updated
2026-07-22T17:54:32Z

Related Entities (4)

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]npm/n8n

AFFECTS (1)

[Software]npm/n8n

HAS_WEAKNESS (1)

[Weakness]Incorrect Authorization

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-w46p-w7w2-fr9g — Ninja Signal Threat Intelligence | Ninja Signal