PT-2025-27832 · N8N · N8N

Agustedone

+3

·

Published

2025-07-03

·

Updated

2025-07-03

·

CVE-2025-52554

CVSS v4.0

4.9

Medium

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:H
Name of the Vulnerable Software and Affected Versions: n8n versions prior to 1.99.1
Description: n8n is a workflow automation platform. An authorization issue was found in the "/rest/executions/:id/stop" endpoint, allowing an authenticated user to stop workflow executions they do not own or that have not been shared with them. This could lead to potential business disruption.
Recommendations: For versions prior to 1.99.1, update to version 1.99.1 to resolve the issue. As a temporary workaround, consider restricting access to the "/rest/executions/:id/stop" endpoint via reverse proxy or API gateway.

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-52554
GHSA-GQ57-V332-7666

Affected Products

N8N