CVE-2026-86996
n8n: Agent Workflow Tool Bypasses Sub-Workflow Caller Policy
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the workflow setting named This workflow can be called by was enforced by the Execute Workflow node but not when a workflow was attached to an Agent as a tool. A user able to build an Agent could invoke a restricted workflow and read its returned data. The affected path is packages/cli/src/modules/agents/tools/workflow-tool-factory.ts, where executeWorkflow omitted SubworkflowPolicyChecker.checkForProject. This issue is fixed in versions 2.37.7 and 2.38.2.
| CWE | CWE-862 |
| Vendor | n8n-io |
| Product | n8n |
| Published | Sep 8, 2026 |
| Last Updated | Sep 9, 2026 |
Stay Ahead of the Next One
Get instant alerts for n8n-io n8n
Be the first to know when new unknown vulnerabilities affecting n8n-io n8n are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
n8n-io / n8n
< 2.37.7 >= 2.38.0, < 2.38.2