Impact
The GitHub Trigger node in n8n discarded the generated webhook secret whenever GitHub returned an HTTP 422 response, while reusing an existing webhook ID. As a result the static workflow data retained a webhook ID but no secret. The X‑Hub‑Signature‑256 verification logic then accepted deliveries without the stored secret, effectively opening the signature check to a fail‑open condition. An attacker who can influence the GitHub trigger payload can therefore cause arbitrary workflow executions with the privileges of the n8n instance.
Affected Systems
All versions of n8n-io n8n prior to the specific release tags 1.123.76, 2.37.7, and 2.38.2 are affected. The issue is resolved in those releases and later.
Risk and Exploitability
The vulnerability has a CVSS score of 6.3, indicating a medium level of severity. No EPSS score is provided and it is not listed in the CISA KEV catalog. The exploit path relies on the GitHub trigger webhook flow; an attacker with access to configure GitHub webhooks or who can trigger an HTTP 422 response at the n8n side can leverage the flaw. Because the signature verification fails open, the attack is relatively straightforward once the conditions are met and can lead to unauthorized workflow execution.
OpenCVE Enrichment
Github GHSA