Impact
n8n versions prior to 1.123.80, 2.39.6, and 2.40.1 do not validate the x-webflow-signature HMAC sent by Webflow for the Webflow Trigger node. Because the signature check is omitted, an attacker who can reach the webhook endpoint can send crafted HTTP requests that appear authentic. When these requests are processed, the n8n workflow engine executes the associated workflow, which can perform actions such as creating, updating, or deleting records, calling external APIs, or running embedded code. The resulting unauthorized execution of workflows compromises the integrity of downstream data and services.
Affected Systems
The vulnerability affects installations of the n8n workflow automation platform produced by n8n‑io. Any release older than n8n 1.123.80, or a 2.x release earlier than 2.39.6 or earlier than 2.40.1, that exposes the Webflow Trigger node webhook endpoint to external or untrusted traffic is susceptible. This includes on‑premise deployments, cloud instances, or managed nn services where the webhook URL is publicly accessible.
Risk and Exploitability
The CVSS score of 6.9 classifies the issue as moderate severity. No EPSS score is publicly available, and the vulnerability is not listed in CISA’s KEV catalog, indicating limited known exploitation. However, the flaw is remotely exploitable over HTTP without requiring authentication. An attacker can send forged webhook payloads directly to the endpoint, causing the n8n instance to execute arbitrary workflows. The lack of signature verification eliminates a critical integrity check, enabling potentially wide‑ranging damage to downstream systems.
OpenCVE Enrichment