PT-2025-54225 · Temporal · Temporal

CVE-2025-14987

·

Publicado

2025-12-30

·

Atualizado

2026-07-30

CVSS v4.0

5.3

Média

VetorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Temporal versions through 1.29.1
Description When the system.enableCrossNamespaceCommands setting is enabled, the Temporal server allows specific workflow task commands—including StartChildWorkflowExecution, SignalExternalWorkflowExecution, and RequestCancelExternalWorkflowExecution—to operate on a namespace different from the one authorized at the gRPC boundary. The frontend authorizes RespondWorkflowTaskCompleted based on the outer request namespace, but the history service later resolves and executes the command using the namespace embedded in command attributes without re-authorizing the caller for that target namespace. This can potentially allow a worker authorized for one namespace to create, signal, or cancel workflows in another namespace.
Recommendations Update to Temporal version 1.27.4 or later. Update to Temporal version 1.28.2 or later. Update to Temporal version 1.29.2 or later.

Exploit

Correção

Incorrect Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-14987
GHSA-HMHP-GH8M-C8XP
GO-2026-4273
OPENSUSE-SU-2026:21483-1
SUSE-SU-2026:0142-1

Produtos afetados

Temporal