Webhook Forgery Vulnerability in n8n GitHub Webhook Trigger
CVE-2026-56357
6.3MEDIUM
What is CVE-2026-56357?
The GitHub Webhook Trigger node in n8n versions prior to 1.123.15 and 2.5.0 has a vulnerability that allows attackers to exploit webhook calls. Due to the failure to enforce HMAC-SHA256 signature verification, unauthorized users can send unsigned POST requests to trigger workflows with any data they choose. This can lead to the manipulation of workflows by spoofing GitHub webhook events, potentially compromising the integrity of automated processes.
Affected Version(s)
n8n 0 < 1.123.15
n8n 2.0.0 < 2.5.0
n8n 1.123.15
