Executive brief
n8n is a workflow automation platform that allows users to create and manage automated tasks. An unauthenticated vulnerability in n8n allows anyone on the network who knows a workflow ID to cancel that workflow's active test webhook, disrupting in-progress testing sessions. This does not affect production webhooks or stored data, but can interfere with legitimate testing and debugging work.
Technical details
The vulnerability exists in the DELETE /${restEndpoint}/test-webhook/:id endpoint, which is registered before authentication middleware is applied in n8n versions before 2.28.0 (and 2.27.4 on the 2.27.x branch). This authorization bypass (CWE-306) allows any unauthenticated network attacker with knowledge of a workflow ID to send a DELETE request and cancel test webhook registrations. The attack requires network access to the n8n instance but no authentication credentials or user interaction. The impact is limited to service disruption of test sessions; production webhooks, workflow state, and persisted data remain unaffected. Patches are available in n8n 2.28.0 and later, or 2.27.4 on the 2.27.x branch.
Affected products
- n8n n8n < 2.28.0, < 2.27.4 on 2.27.x branch
Timeline
- 2026-07-22: disclosed
- 2026-07-22: advisory: Published as GHSA-h9fm-xcv2-qfw3 then withdrawn as duplicate of GHSA-33q9-f52j-gc75
- 2026-07-08: patched: Patches released in n8n 2.28.0 and 2.27.4