PT-2026-51415 · N8N · N8N
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
n8n versions prior to 1.123.15
n8n versions prior to 2.5.0
Description
The GitHub Webhook Trigger node fails to implement HMAC-SHA256 signature verification, which is a mechanism used to authenticate that a webhook delivery actually comes from GitHub. This allows an attacker who knows the webhook URL to send unsigned POST requests to trigger workflows with arbitrary data, effectively spoofing GitHub webhook events.
Recommendations
Update to version 1.123.15 or later.
Update to version 2.5.0 or later.
Limit workflow creation and editing permissions to fully trusted users only.
Restrict network access to the n8n webhook endpoint to known GitHub webhook IP ranges.
Exploit
Fix
Authentication Bypass by Spoofing
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
N8N