Description
n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 fail to verify the x-webflow-signature HMAC in the Webflow Trigger node webhook handler. Unauthenticated attackers can send forged webhook requests with attacker-controlled payloads to trigger workflows and manipulate downstream actions like record creation or API calls.
Published: 2026-10-01
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized workflow execution
Action: Immediate Patch
AI Analysis

Impact

n8n versions prior to 1.123.80, 2.39.6, and 2.40.1 do not validate the x-webflow-signature HMAC sent by Webflow for the Webflow Trigger node. Because the signature check is omitted, an attacker who can reach the webhook endpoint can send crafted HTTP requests that appear authentic. When these requests are processed, the n8n workflow engine executes the associated workflow, which can perform actions such as creating, updating, or deleting records, calling external APIs, or running embedded code. The resulting unauthorized execution of workflows compromises the integrity of downstream data and services.

Affected Systems

The vulnerability affects installations of the n8n workflow automation platform produced by n8n‑io. Any release older than n8n 1.123.80, or a 2.x release earlier than 2.39.6 or earlier than 2.40.1, that exposes the Webflow Trigger node webhook endpoint to external or untrusted traffic is susceptible. This includes on‑premise deployments, cloud instances, or managed nn services where the webhook URL is publicly accessible.

Risk and Exploitability

The CVSS score of 6.9 classifies the issue as moderate severity. No EPSS score is publicly available, and the vulnerability is not listed in CISA’s KEV catalog, indicating limited known exploitation. However, the flaw is remotely exploitable over HTTP without requiring authentication. An attacker can send forged webhook payloads directly to the endpoint, causing the n8n instance to execute arbitrary workflows. The lack of signature verification eliminates a critical integrity check, enabling potentially wide‑ranging damage to downstream systems.

Generated by OpenCVE AI on October 1, 2026 at 14:13 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade n8n to version 1.123.80 or newer, or to 2.39.6 or 2.40.1 where the signature verification bug is fixed.
  • Restrict network access to the Webflow Trigger webhook endpoint so that only trusted IPs or internal networks can reach it, using firewall rules or reverse proxy restrictions.
  • If immediate upgrade is not feasible, add a pre‑processing step that validates the x-webflow-signature HMAC against the shared secret before allowing the workflow to run; reject any requests that fail validation.
  • Monitor workflow execution logs for unexpected or unusual triggers and review audit trails regularly to detect potential abuse.

Generated by OpenCVE AI on October 1, 2026 at 14:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 11:00:00 +0000

Type Values Removed Values Added
Description n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 fail to verify the x-webflow-signature HMAC in the Webflow Trigger node webhook handler. Unauthenticated attackers can send forged webhook requests with attacker-controlled payloads to trigger workflows and manipulate downstream actions like record creation or API calls.
Title n8n before 1.123.80, 2.39.6, and 2.40.1 Missing Webhook Signature Verification
First Time appeared N8n
N8n n8n
Weaknesses CWE-347
CPEs cpe:2.3:a:n8n:n8n:*:*:*:*:*:*:*:*
Vendors & Products N8n
N8n n8n
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-01T15:02:26.087Z

Reserved: 2026-09-30T10:52:32.248Z

Link: CVE-2026-103245

cve-icon Vulnrichment

Updated: 2026-10-01T15:02:22.339Z

cve-icon NVD

Status : Deferred

Published: 2026-10-01T11:17:17.670

Modified: 2026-10-01T15:17:26.180

Link: CVE-2026-103245

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T15:30:08Z

Weaknesses
  • CWE-347

    Improper Verification of Cryptographic Signature