n8n
cpe:2.3:a:n8n:n8n:*:*:*:*:node.js:*:*
- < 1.123.18
- >= 2.0.0, < 2.6.2
A vulnerability exists in n8n versions prior to 1.123.18 and between 2.0.0 and 2.6.2, where the ZendeskTrigger node does not properly verify HMAC-SHA256 signatures on webhooks from Zendesk. This flaw allows attackers who are aware of the webhook URL to send unsigned POST requests, triggering workflows with arbitrary malicious data. The lack of signature verification enables the injection of crafted payloads into the workflow.
Exploitation of this vulnerability allows for webhook forgery, where unsigned POST requests can be used to manipulate workflows in n8n by injecting malicious data, potentially leading to unauthorized actions or data processing within the application.
Users can upgrade to n8n versions 2.6.2 or 1.123.18 to address this vulnerability. If an immediate upgrade is not possible, it is recommended to limit workflow creation and editing permissions to trusted users and to restrict network access to the n8n webhook endpoint to known Zendesk IP ranges.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.