CyberRota Analysis
AI-GeneratedThe GitHub Trigger in n8n versions prior to 1.123.76, 2.37.7, and 2.38.2 is vulnerable due to improper handling of webhook secrets when a 422 HTTP error occurs, allowing for the acceptance of deliveries without proper verification. This flaw can lead to unauthorized access and potential exploitation of workflows that rely on GitHub webhooks. Organizations using affected versions of n8n should prioritize updating to the fixed versions to mitigate this security risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the GitHub Trigger generated a webhook secret but discarded it when GitHub returned HTTP 422 and the node reused an existing webhook. Workflow static data then retained webhookId without webhookSecret, and X-Hub-Signature-256 verification accepted deliveries without a stored secret. The affected logic includes packages/nodes-base/nodes/Github/GithubTriggerHelpers.ts and the 422 webhook reuse path. This issue is fixed in versions 1.123.76, 2.37.7 and 2.38.2.
Related CVEs
Other vulnerabilities affecting the same vendor(s)