Количество 2
Количество 2
CVE-2026-56357
n8n before 1.123.15 and 2.5.0 contains a webhook forgery vulnerability in the GitHub Webhook Trigger node that fails to implement HMAC-SHA256 signature verification. Attackers who know the webhook URL can send unsigned POST requests to trigger workflows with arbitrary data, spoofing GitHub webhook events.
GHSA-mqpr-49jj-32rc
n8n: Webhook Forgery on Github Webhook Trigger
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-56357 n8n before 1.123.15 and 2.5.0 contains a webhook forgery vulnerability in the GitHub Webhook Trigger node that fails to implement HMAC-SHA256 signature verification. Attackers who know the webhook URL can send unsigned POST requests to trigger workflows with arbitrary data, spoofing GitHub webhook events. | CVSS3: 4 | 0% Низкий | 3 месяца назад | |
GHSA-mqpr-49jj-32rc n8n: Webhook Forgery on Github Webhook Trigger | CVSS3: 4 | 0% Низкий | 6 месяцев назад |
Уязвимостей на страницу