Two authorization bypasses in n8n’s AI agents let low-privileged users perform actions beyond those allowed by their role, including executing arbitrary nodes and exfiltrating credentials in cleartext. In some configurations, the same attack path can also give a read-only user command execution on the n8n host.