CVE-2026-56357

n8n before 1.123.15 and 2.5.0 contains a webhook forgery vulnerability in the GitHub Webhook Trigger node that fails to implement HMAC-SHA256 signature verification. Attackers who know the webhook URL can send unsigned POST requests to trigger workflows with arbitrary data, spoofing GitHub webhook events.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:n8n:n8n:*:*:*:*:community:node.js:*:*
cpe:2.3:a:n8n:n8n:*:*:*:*:enterprise:node.js:*:*
cpe:2.3:a:n8n:n8n:*:*:*:*:community:node.js:*:*
cpe:2.3:a:n8n:n8n:*:*:*:*:enterprise:node.js:*:*

History

24 Jun 2026, 16:47

Type Values Removed Values Added
References () https://github.com/n8n-io/n8n/security/advisories/GHSA-mqpr-49jj-32rc - () https://github.com/n8n-io/n8n/security/advisories/GHSA-mqpr-49jj-32rc - Vendor Advisory
References () https://www.vulncheck.com/advisories/n8n-webhook-forgery-via-missing-hmac-sha256-signature-verification-in-github-webhook-trigger - () https://www.vulncheck.com/advisories/n8n-webhook-forgery-via-missing-hmac-sha256-signature-verification-in-github-webhook-trigger - Third Party Advisory
CPE cpe:2.3:a:n8n:n8n:*:*:*:*:enterprise:node.js:*:*
cpe:2.3:a:n8n:n8n:*:*:*:*:community:node.js:*:*
First Time N8n
N8n n8n

22 Jun 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-22 22:16

Updated : 2026-06-24 16:47


NVD link : CVE-2026-56357

Mitre link : CVE-2026-56357

CVE.ORG link : CVE-2026-56357


JSON object : View

Products Affected

n8n

  • n8n
CWE
CWE-290

Authentication Bypass by Spoofing