Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wgjf-2hg5-2533

Опубликовано: 08 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.3
CVSS3: 4

Описание

n8n before versions 1.123.18 and 2.6.2 fails to verify HMAC-SHA256 signatures on Zendesk webhooks in the ZendeskTrigger node. Attackers who know the webhook URL can send unsigned POST requests to trigger workflows with arbitrary malicious data.

n8n before versions 1.123.18 and 2.6.2 fails to verify HMAC-SHA256 signatures on Zendesk webhooks in the ZendeskTrigger node. Attackers who know the webhook URL can send unsigned POST requests to trigger workflows with arbitrary malicious data.

EPSS

Процентиль: 24%
0.00314
Низкий

6.3 Medium

CVSS4

4 Medium

CVSS3

Дефекты

CWE-290

Связанные уязвимости

CVSS3: 4
nvd
2 месяца назад

n8n before versions 1.123.18 and 2.6.2 fails to verify HMAC-SHA256 signatures on Zendesk webhooks in the ZendeskTrigger node. Attackers who know the webhook URL can send unsigned POST requests to trigger workflows with arbitrary malicious data.

EPSS

Процентиль: 24%
0.00314
Низкий

6.3 Medium

CVSS4

4 Medium

CVSS3

Дефекты

CWE-290