CVE-2026-86080
n8n: GitHub Trigger 422 Reuse Path Skips Webhook Secret Storage, Causing Signature Verification to Fail-Open
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the GitHub Trigger generated a webhook secret but discarded it when GitHub returned HTTP 422 and the node reused an existing webhook. Workflow static data then retained webhookId without webhookSecret, and X-Hub-Signature-256 verification accepted deliveries without a stored secret. The affected logic includes packages/nodes-base/nodes/Github/GithubTriggerHelpers.ts and the 422 webhook reuse path. This issue is fixed in versions 1.123.76, 2.37.7 and 2.38.2.
| CWE | CWE-347 |
| Vendor | n8n-io |
| Product | n8n |
| Published | Sep 8, 2026 |
| Last Updated | Sep 9, 2026 |
Stay Ahead of the Next One
Get instant alerts for n8n-io n8n
Be the first to know when new unknown vulnerabilities affecting n8n-io n8n are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
n8n-io / n8n
>= 2.38.0, < 2.38.2 >= 2.0.0, < 2.37.7 < 1.123.76
References
github.com: https://github.com/n8n-io/n8n/security/advisories/GHSA-5m98-cgcr-xx3q github.com: https://github.com/n8n-io/n8n/releases/tag/[email protected] github.com: https://github.com/n8n-io/n8n/releases/tag/[email protected] github.com: https://github.com/n8n-io/n8n/releases/tag/[email protected]