CVE-2026-103245
Deferred Deferred - Pending Action

Unauthenticated Webhook Forgery in n8n

Vulnerability report for CVE-2026-103245, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: VulnCheck

Description

n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 fail to verify the x-webflow-signature HMAC in the Webflow Trigger node webhook handler. Unauthenticated attackers can send forged webhook requests with attacker-controlled payloads to trigger workflows and manipulate downstream actions like record creation or API calls.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
n8n n8n to 1.123.80 (exc)
n8n n8n to 2.39.6 (exc)
n8n n8n to 2.40.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-347 The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-103245 is a vulnerability in n8n versions before 1.123.80, 2.0.0 before 2.39.6, and 2.40.0 before 2.40.1 where the Webflow Trigger node fails to verify the x-webflow-signature HMAC in webhook handlers. This allows unauthenticated attackers to send forged webhook requests with attacker-controlled payloads, triggering workflows and manipulating downstream actions like record creation or API calls.

Detection Guidance

Check if your n8n instance is running a vulnerable version by running: n8n --version. Inspect webhook logs for suspicious requests without valid x-webflow-signature headers. Monitor for unauthorized workflow triggers or unexpected downstream actions like record creation or API calls.

Impact Analysis

This vulnerability could allow unauthorized individuals to manipulate workflows by sending fake webhook requests. This might lead to unintended actions such as creating or modifying records, sending messages, or making unauthorized API calls, potentially causing data breaches or workflow disruptions.

Mitigation Strategies

Upgrade n8n to a patched version (1.123.80 or later, 2.39.6 or later, or 2.40.1 or later). Temporarily deactivate affected Webflow Trigger workflows until patched. Restrict network access to the webhook endpoint using firewalls or network policies. Limit n8n instance access to trusted users only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103245. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart