PT-2026-2559 · N8N · N8N

Published

2026-01-13

·

Updated

2026-01-13

·

CVE-2025-68949

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions n8n versions 1.36.0 through 2.1.9
Description n8n is a workflow automation platform where the Webhook node’s IP whitelist validation incorrectly used partial string matching instead of exact IP comparison. This allowed incoming requests to be accepted if the source IP address contained the configured whitelist entry as a substring. Both IPv4 and IPv6 addresses were impacted, potentially allowing an attacker with a non-whitelisted IP to bypass access restrictions if their IP shared a partial prefix with a trusted address. The issue affected instances relying on IP-based access controls to restrict webhook access.
Recommendations Update to version 2.2.0 or later.

Exploit

Fix

Improper Access Control

Use of Externally-Controlled Format String

Weakness Enumeration

Related Identifiers

BDU:2026-00784
CVE-2025-68949
GHSA-W96V-GF22-CRWP

Affected Products

N8N