Feed/CVE-2026-65015
CVE-2026-65015HIGHCVSS 8.8

CVE-2026-65015

Published Jul 22, 2026·Updated Jul 28, 2026

NVD Description

n8n versions before 2.30.1 contain a privilege escalation vulnerability in the AI Agents feature where the node-execution tool lacks proper authorization checks. A Project Viewer user can escalate privileges by chatting with an agent that has node tools enabled, executing arbitrary nodes and accessing credential secrets without proper authorization verification.

Affected Packages (1)

n8nNPM
From 2.30.0
Fixed in 2.30.1

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free