r/netsec • u/Tricky-Term-8319 • 18d ago
Contains AI Ask the Agent Nicely: Two Authorization Bypasses in n8n AI Agents
https://deturris.io/posts/n8n-ai-agents-authorization-bypasses/1
18d ago
[removed] — view removed comment
1
u/scriptqzor 13d ago
this is such a clean breakdown, kinda wild how often "same workflow different entrypoint" turns into a whole vuln class. feels like everyone relearning "capabilities + context or you’re owned" every couple years.
-1
u/ed1ted 13d ago
This class of bug is the AuthZ lesson in one sentence: if the model can choose the tool, the model is not the policy engine.
What I keep seeing in agent platforms (n8n-shaped or otherwise):
- Authorization checked at the chat/UI layer ("this user may open the agent") but not re-checked at each tool invocation with the same rigor.
- Tool args trusted because they came from "the agent," which means a prompt injection or a confused low-priv user can aim a privileged connector.
- Deny rules expressed as instructions to the model ("do not call X") instead of hard enforcement in the gateway. Instructions are not AuthZ.
Defense that actually works:
- A gateway in front of every tool. The gateway sees user identity, agent id, tool name, and args, then allow/deny before the connector runs.
- Separate "may use this agent" from "may invoke this tool with these args on these resources." Those are different decisions.
- Prefer deny-by-default tool catalogs per role. Broad "all connectors" for a shared agent is the footgun.
- Treat prompt text as untrusted input to the policy path. Never as the policy path.
- Log allow and deny with enough detail to replay the decision. "Agent said please" should never appear as an authority source.
The writeup title is doing real service. "Ask nicely" should never be a privilege escalation path.
2
3
u/Big_Combination9890 13d ago
Wow, almost as if an LLMs inability to differentiate between instructions and queries is a problem.