Authentication Bypass by Spoofing in n8n - #VU127202
Published: April 23, 2026
n8n
Detailed vulnerability description
The vulnerability allows a remote attacker to inject arbitrary data into a workflow.
The vulnerability exists due to authentication bypass by spoofing in the ZendeskTrigger node when handling webhook POST requests. A remote attacker can send unsigned POST requests to inject arbitrary data into a workflow.
Exploitation requires knowledge of the webhook URL for a workflow using the ZendeskTrigger node.