Skip to content

fix(core): Prevent unauthorised workflow termination #16405

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 7 commits into
base: master
Choose a base branch
from

Conversation

MarcL
Copy link
Contributor

@MarcL MarcL commented Jun 16, 2025

Summary

This PR addresses a security vulnerability that allowed authenticated users to terminate any workflow execution, regardless of ownership. Previously, the 'stop workflow' endpoint improperly used a direct parameter reference, bypassing user-scoped authorisation. This fix ensures that only the workflow owner can stop an execution.

Related Linear tickets, Github issues, and Community forum posts

Fixes: PAY-2960

Review / Merge checklist

  • PR title and summary are descriptive. (conventions)
  • [ ] Docs updated or follow-up ticket created.
  • Tests included
  • PR Labeled with release/backport (if the PR is an urgent fix that needs to be backported)

@MarcL MarcL changed the title fix: Prevent unauthorised workflow termination fix(core): Prevent unauthorised workflow termination Jun 16, 2025
Copy link
Contributor

@cubic-dev-ai cubic-dev-ai bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

cubic found 3 issues across 5 files. Review them in cubic.dev

React with 👍 or 👎 to teach cubic. Tag @cubic-dev-ai to give specific feedback.

@n8n-assistant n8n-assistant bot added core Enhancement outside /nodes-base and /editor-ui n8n team Authored by the n8n team labels Jun 16, 2025
Copy link

codecov bot commented Jun 16, 2025

Codecov Report

All modified and coverable lines are covered by tests ✅

📢 Thoughts on this report? Let us know!

Copy link
Contributor

@guillaumejacquart guillaumejacquart left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Some comments

Copy link
Contributor

✅ All Cypress E2E specs passed

@n8n-io n8n-io deleted a comment from dionatasvieir Jun 17, 2025
Copy link
Contributor

@guillaumejacquart guillaumejacquart left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good to me

Copy link
Contributor

⚠️ Some Cypress E2E specs are failing, please fix them before merging

1 similar comment
Copy link
Contributor

⚠️ Some Cypress E2E specs are failing, please fix them before merging

Copy link
Contributor

✅ All Cypress E2E specs passed

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
core Enhancement outside /nodes-base and /editor-ui n8n team Authored by the n8n team
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants