Webhook Forgery Vulnerability in n8n GitHub Webhook Trigger
CVE-2026-56357

6.3MEDIUM

Key Information:

Vendor

N8n

Status
Vendor
CVE Published:
22 June 2026

What is CVE-2026-56357?

The GitHub Webhook Trigger node in n8n versions prior to 1.123.15 and 2.5.0 has a vulnerability that allows attackers to exploit webhook calls. Due to the failure to enforce HMAC-SHA256 signature verification, unauthorized users can send unsigned POST requests to trigger workflows with any data they choose. This can lead to the manipulation of workflows by spoofing GitHub webhook events, potentially compromising the integrity of automated processes.

Affected Version(s)

n8n 0 < 1.123.15

n8n 2.0.0 < 2.5.0

n8n 1.123.15

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

simonkoeck
.