PT-2026-50174 · N8N · N8N
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
n8n versions prior to 2.25.7
n8n versions prior to 2.26.2
Description
The
MicrosoftAgent365Trigger and StripeTrigger nodes fail to validate inbound requests. This allows an unauthenticated attacker with knowledge of the webhook URL to submit a forged payload, triggering workflow execution with attacker-controlled data.Recommendations
Update to version 2.25.7 or later.
Update to version 2.26.2 or later.
Deactivate any workflows using the
MicrosoftAgent365Trigger or StripeTrigger nodes as a temporary measure.
Restrict network access to the n8n webhook endpoint to trusted sources only.Exploit
Fix
Authentication Bypass by Spoofing
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
N8N