VDB
KO
MEDIUM

GHSA-33q9-f52j-gc75

n8n: Unauthenticated Endpoint Allows Cancellation of Any User's Active Test Webhook

Quick fix

GHSA-33q9-f52j-gc75 — n8n: upgrade to the fixed version with the command below.

npm install n8n@2.27.4

Details

## Impact The `DELETE /${restEndpoint}/test-webhook/:id` route is registered before the authentication middleware is applied, allowing any unauthenticated network caller who knows a workflow ID to cancel that workflow's active test webhook registration.

The impact is limited to disrupting in-progress test sessions. Production webhooks, persistent workflow state, and stored data are not affected.

## Patches Users should upgrade to the patched version once available to remediate the vulnerability.

## Workarounds If upgrading is not immediately possible, administrators should consider the following temporary mitigations: - Restrict network access to the n8n instance to fully trusted users only. - Place the n8n instance behind a reverse proxy or firewall that requires authentication before reaching the REST API.

These workarounds do not fully remediate the risk and should only be used as short-term mitigation measures.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / n8n
Introduced in: 0 Fixed in: 2.27.4
Fix npm install n8n@2.27.4

References