CVE-2026-56357: n8n

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

n8n before 1.123.15 and 2.5.0 contains a webhook forgery vulnerability in the GitHub Webhook Trigger node that fails to implement HMAC-SHA256 signature verification. Attackers who know the webhook URL can send unsigned POST requests to trigger workflows with arbitrary data, spoofing GitHub webhook events.

Affected products

  • n8n n8n: before 1.123.15 (fixed in 1.123.15); from 2.0.0, before 2.5.0 (fixed in 2.5.0)

Published 2026-06-22. Last modified 2026-06-24.