Input Validation Flaw in n8n Workflow Automation Platform
CVE-2026-54308

6.3MEDIUM

Key Information:

Vendor

N8n-io

Status
Vendor
CVE Published:
23 June 2026

What is CVE-2026-54308?

The n8n workflow automation platform prior to versions 2.25.7 and 2.26.2 contains an input validation flaw in the MicrosoftAgent365Trigger and StripeTrigger nodes. This vulnerability allows unauthenticated attackers, who possess knowledge of the webhook URL, to send forged payloads. Consequently, malicious actors can execute workflows using manipulated data, potentially compromising the integrity and security of the automated processes. The issue has been addressed in the subsequent software releases, ensuring enhanced validation of incoming requests.

Affected Version(s)

n8n >= 2.26.0, < 2.26.2 < 2.26.0, 2.26.2

n8n < 2.25.7 < 2.25.7

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.