GHSA-33q9-f52j-gc75: n8n: Unauthenticated Endpoint Allows Cancellation of Any User's Active Test Webhook
Summary
A vulnerability in n8n (a workflow automation tool) allows anyone on the network to cancel another user's active test webhook without logging in, because an endpoint wasn't protected by authentication checks. The impact is limited to disrupting testing sessions, not production systems or stored data.
Solution / Mitigation
Users should upgrade to the patched version once available. As temporary workarounds if upgrading isn't possible: restrict network access to n8n to trusted users only, or place n8n behind a reverse proxy or firewall (a security layer that filters traffic) requiring authentication before API access. These workarounds do not fully remediate the risk and should only be used as short-term measures.
Vulnerability Details
EPSS: 0.0%
Yes
July 22, 2026
Classification
Affected Vendors
Affected Packages
Related Issues
Original source: https://github.com/advisories/GHSA-33q9-f52j-gc75
First tracked: July 22, 2026 at 08:01 PM
Classified by LLM (prompt v3) · confidence: 82%