THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-7hgx-277f-7vmg (medium) — n8n: Agent Workflow Tool Bypasses Sub-Workflow Caller Policy

[GHSA] GHSA-7hgx-277f-7vmg (medium) — n8n: Agent Workflow Tool Bypasses Sub-Workflow Caller Policy

medgithub_advisoriesPublished 2026-09-08

GHSA-7hgx-277f-7vmg Severity: medium CVE: CVE-2026-86996

n8n: Agent Workflow Tool Bypasses Sub-Workflow Caller Policy

## Impact

A workflow's "_This workflow can be called by_" setting was enforced by the Execute Workflow node but was not consulted when the same workflow was attached to an Agent as a tool. A user who could build an Agent could therefore call a workflow that its owner had restric

Indicators of compromise

Original source: https://github.com/advisories/GHSA-7hgx-277f-7vmg