Authentication Bypass by Spoofing in n8n - #VU127203

 

Authentication Bypass by Spoofing in n8n - #VU127203

Published: April 23, 2026


Vulnerability identifier: #VU127203
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-290
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to trigger the workflow with arbitrary data.

The vulnerability exists due to authentication bypass by spoofing in the GitHub Webhook Trigger node when handling webhook POST requests. A remote attacker can send unsigned POST requests to trigger the workflow with arbitrary data.

Exploitation requires knowledge of the webhook URL.


Affected software

n8n

Remediation

Install security update from vendor's website.

n8n - addressed in versions 1.123.15, 2.5.0

External References

Related Security Bulletins