Executive brief
n8n is an automation platform used to connect different software services and automate business tasks. A security flaw in the Microsoft Agent 365 and Stripe connectors allows unauthorized individuals to trigger automated workflows by sending fake data to specific web addresses. This could lead to unauthorized actions being performed within your connected business applications or the processing of fraudulent data.
Technical details
A missing token validation vulnerability (CWE-290) exists in the MicrosoftAgent365Trigger and StripeTrigger nodes of n8n. The affected components do not properly verify the authenticity of inbound webhook requests. An unauthenticated attacker who discovers or guesses a valid webhook URL can submit a forged JSON payload, causing the workflow to execute using attacker-controlled data. This can lead to unauthorized data processing or side effects in downstream nodes. The issue is resolved in versions 2.25.7 and 2.26.2.
Affected products
- n8n-io n8n < 2.25.7, >= 2.26.0 < 2.26.2
Timeline
- 2026-06-10: advisory: GitHub advisory published by vendor
- 2026-06-23: disclosed: CVE published to NVD