PT-2026-51415 · N8N · N8N

·

CVE-2026-56357

·

Published

2026-02-26

·

Updated

2026-06-24

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions n8n versions prior to 1.123.15 n8n versions prior to 2.5.0
Description The GitHub Webhook Trigger node fails to implement HMAC-SHA256 signature verification, which is a mechanism used to authenticate that a webhook delivery actually comes from GitHub. This allows an attacker who knows the webhook URL to send unsigned POST requests to trigger workflows with arbitrary data, effectively spoofing GitHub webhook events.
Recommendations Update to version 1.123.15 or later. Update to version 2.5.0 or later. Limit workflow creation and editing permissions to fully trusted users only. Restrict network access to the n8n webhook endpoint to known GitHub webhook IP ranges.

Exploit

Fix

Authentication Bypass by Spoofing

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56357
GHSA-MQPR-49JJ-32RC

Affected Products

N8N