Improper Verification of Cryptographic Signature in n8n - #VU153005
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote attacker to approve waiting executions without authorization.
The vulnerability exists due to improper verification of a cryptographic signature in the waiting-webhook endpoint when processing a Send-and-Wait node reference in an alternate form. A remote attacker can send a request containing an alternate Send-and-Wait node reference and a resume token to approve a waiting execution.
Exploitation requires possession of the execution's resume token.