n8n before versions 1.123.18 and 2.6.2 fails to verify HMAC-SHA256 signatures on Zendesk webhooks in the ZendeskTrigger node. Attackers who know the webhook URL can send unsigned POST requests to trigger workflows with arbitrary malicious data.
| Vendor | Product | Versions |
|---|---|---|
| n8n | n8n | 0, 2.0.0 |
Updated severity to CRITICAL, marked exploit availability as false, and added affected versions 1.123.17 and 2.6.1.
Initial creation