CVE-2026-56357

n8n before 1.123.15 and 2.5.0 contains a webhook forgery vulnerability in the GitHub Webhook Trigger node that fails to implement HMAC-SHA256 signature verification. Attackers who know the webhook URL can send unsigned POST requests to trigger workflows with arbitrary data, spoofing GitHub webhook events.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:n8n:n8n:*:*:*:*:community:node.js:*:*
cpe:2.3:a:n8n:n8n:*:*:*:*:enterprise:node.js:*:*
cpe:2.3:a:n8n:n8n:*:*:*:*:community:node.js:*:*
cpe:2.3:a:n8n:n8n:*:*:*:*:enterprise:node.js:*:*

History

No history.

Information

Published : 2026-06-22 22:16

Updated : 2026-06-24 16:47


NVD link : CVE-2026-56357

Mitre link : CVE-2026-56357

CVE.ORG link : CVE-2026-56357


JSON object : View

Products Affected

n8n

  • n8n
CWE
CWE-290

Authentication Bypass by Spoofing