Improper Verification of Cryptographic Signature in n8n - #VU150757
Published: September 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to inject forged events into workflows.
The vulnerability exists due to improper verification of cryptographic signatures in the Webflow Trigger node webhook handler when handling HTTP POST requests to the webhook URL. A remote attacker can send a forged request to inject forged events into workflows.