Input Validation Flaw in n8n Workflow Automation Platform
CVE-2026-54308
6.3MEDIUM
What is CVE-2026-54308?
The n8n workflow automation platform prior to versions 2.25.7 and 2.26.2 contains an input validation flaw in the MicrosoftAgent365Trigger and StripeTrigger nodes. This vulnerability allows unauthenticated attackers, who possess knowledge of the webhook URL, to send forged payloads. Consequently, malicious actors can execute workflows using manipulated data, potentially compromising the integrity and security of the automated processes. The issue has been addressed in the subsequent software releases, ensuring enhanced validation of incoming requests.
Affected Version(s)
n8n >= 2.26.0, < 2.26.2 < 2.26.0, 2.26.2
n8n < 2.25.7 < 2.25.7
