Description
n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the GitHub Trigger generated a webhook secret but discarded it when GitHub returned HTTP 422 and the node reused an existing webhook. Workflow static data then retained webhookId without webhookSecret, and X-Hub-Signature-256 verification accepted deliveries without a stored secret. The affected logic includes packages/nodes-base/nodes/Github/GithubTriggerHelpers.ts and the 422 webhook reuse path. This issue is fixed in versions 1.123.76, 2.37.7 and 2.38.2.
Published: 2026-09-08
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Workflow Execution via Unprotected Webhook
Action: Patch Immediately
AI Analysis

Impact

The GitHub Trigger node in n8n discarded the generated webhook secret whenever GitHub returned an HTTP 422 response, while reusing an existing webhook ID. As a result the static workflow data retained a webhook ID but no secret. The X‑Hub‑Signature‑256 verification logic then accepted deliveries without the stored secret, effectively opening the signature check to a fail‑open condition. An attacker who can influence the GitHub trigger payload can therefore cause arbitrary workflow executions with the privileges of the n8n instance.

Affected Systems

All versions of n8n-io n8n prior to the specific release tags 1.123.76, 2.37.7, and 2.38.2 are affected. The issue is resolved in those releases and later.

Risk and Exploitability

The vulnerability has a CVSS score of 6.3, indicating a medium level of severity. No EPSS score is provided and it is not listed in the CISA KEV catalog. The exploit path relies on the GitHub trigger webhook flow; an attacker with access to configure GitHub webhooks or who can trigger an HTTP 422 response at the n8n side can leverage the flaw. Because the signature verification fails open, the attack is relatively straightforward once the conditions are met and can lead to unauthorized workflow execution.

Generated by OpenCVE AI on September 9, 2026 at 08:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade n8n to version 1.123.76, 2.37.7, or 2.38.2 or later where the flaw is fixed.
  • Regenerate and reconfigure any existing GitHub webhook secrets to ensure secrets are stored properly.
  • Monitor for HTTP 422 responses from GitHub triggers and investigate any unexpected webhook activity.

Generated by OpenCVE AI on September 9, 2026 at 08:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-5m98-cgcr-xx3q n8n: GitHub Trigger 422 Reuse Path Skips Webhook Secret Storage, Causing Signature Verification to Fail-Open
History

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared N8n
N8n n8n
CPEs cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*
Vendors & Products N8n
N8n n8n
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Wed, 09 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the GitHub Trigger generated a webhook secret but discarded it when GitHub returned HTTP 422 and the node reused an existing webhook. Workflow static data then retained webhookId without webhookSecret, and X-Hub-Signature-256 verification accepted deliveries without a stored secret. The affected logic includes packages/nodes-base/nodes/Github/GithubTriggerHelpers.ts and the 422 webhook reuse path. This issue is fixed in versions 1.123.76, 2.37.7 and 2.38.2.
Title n8n: GitHub Trigger 422 Reuse Path Skips Webhook Secret Storage, Causing Signature Verification to Fail-Open
Weaknesses CWE-347
References
Metrics cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-09T13:16:31.787Z

Reserved: 2026-09-04T19:34:03.100Z

Link: CVE-2026-86080

cve-icon Vulnrichment

Updated: 2026-09-09T13:16:28.153Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T22:19:16.953

Modified: 2026-09-11T18:21:38.147

Link: CVE-2026-86080

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T20:06:04Z

Weaknesses
  • CWE-347

    Improper Verification of Cryptographic Signature