Improper Verification of Cryptographic Signature in n8n - #VU150757

 

Improper Verification of Cryptographic Signature in n8n - #VU150757

Published: September 17, 2026


Vulnerability identifier: #VU150757
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-347
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to inject forged events into workflows.

The vulnerability exists due to improper verification of cryptographic signatures in the Webflow Trigger node webhook handler when handling HTTP POST requests to the webhook URL. A remote attacker can send a forged request to inject forged events into workflows.


Affected software

n8n

Remediation

Install security update from vendor's website.

n8n - addressed in versions 1.123.80, 2.39.6, 2.40.1

External References

Related Security Bulletins