CVE-2025-52554 - CVE House
Back to Database
Status published Medium CVE-2025-52554

n8n Improper Authorization in Workflow Execution Stop Endpoint Allows Terminating Other Users’ Workflows

Vulnerability Description

n8n is a workflow automation platform. Prior to version 1.99.1, an authorization vulnerability was discovered in the /rest/executions/:id/stop endpoint of n8n. An authenticated user can stop workflow executions that they do not own or that have not been shared with them, leading to potential business disruption. This issue has been patched in version 1.99.1. A workaround involves restricting access to the /rest/executions/:id/stop endpoint via reverse proxy or API gateway.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-52554

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

n8n
Vulnerable Versions:
< 1.99.1

Timeline

Official Publish: July 3rd, 2025
Last Modified: July 3rd, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)