n8n npm Package Vulnerability: Unauthenticated Endpoint Exposes Test Webhooks
An early warning has been issued for a vulnerability in the n8n npm package, where an unauthenticated endpoint allows the cancellation of any user's active test webhook. Users of affected versions should assess their exposure and prepare to upgrade once a patch is available.
What happened
Reportedly, the n8n npm package contains an unauthenticated endpoint that enables the cancellation of any user's active test webhook. This vulnerability appears to impact in-progress test sessions but does not compromise user data or system integrity. The affected versions span a wide range, from 0 to 2.32.0, with specific fixed versions listed in the threat data. Professionals using n8n should review the provided version ranges to determine if their installations are vulnerable. It is recommended to monitor for updates and apply patches as soon as they become available to mitigate potential risks.
How 0Day mitigates this
n8n is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.