CVE-2026-21894Disclosure(n8n / n8n)

LOWCVSS 6.5 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

n8n is an open source workflow automation platform. In versions from 0.150.0 to before 2.2.2, an authentication bypass vulnerability in the Stripe Trigger node allows unauthenticated parties to trigger workflows by sending forged Stripe webhook events. The Stripe Trigger creates and stores a Stripe webhook signing secret when registering the webhook endpoint, but incoming webhook requests were not verified against this secret. As a result, any HTTP client that knows the webhook URL could send a POST request containing a matching event type, causing the workflow to execute as if a legitimate Stripe event had been received. This issue affects n8n users who have active workflows using the Stripe Trigger node. An attacker could potentially fake payment or subscription events and influence downstream workflow behavior. The practical risk is reduced by the fact that the webhook URL contains a high-entropy UUID; however, authenticated n8n users with access to the workflow can view this webhook ID. This issue has been patched in version 2.2.2. A temporary workaround for this issue involves users deactivating affected workflows or restricting access to workflows containing Stripe Trigger nodes to trusted users only.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-290

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • n8n

Threat summary

  • Public PoC is present in monitored signal
  • 1 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
n8n

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-22: 1PoC Mentioned / Linked · 2026-04-22: 1Technical Details · 2026-04-22: 104-22
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • Jan Voldán@jan_voldan
    Disclosure

    CVE-2026-21894 confirmed it: missing Stripe webhook signature verification allowed forged payment events to trigger real workflows. Your webhook is a URL. It accepts POST requests. Without signature verification, anyone can send a fake checkout.session.completed and get premium access. Most common cause in AI-generated apps: body parsing problem. Framework parses JSON before handler gets it. Signature verification fails. Developer disables it "temporarily." Ships to production. Hundreds of Stack Overflow questions document this exact pattern. Your app processes real Stripe events correctly. Nothing looks wrong. The vulnerability is invisible until someone sends a fake event. -> http://vibecodiq.com/go/webhook-trust-gap/11

    Post summary

    The post announces that CVE-2026-21894 is a genuine vulnerability stemming from missing Stripe webhook signature verification, which could allow forged events to trigger real workflows, and it references an external link for further details.

    1001040
    8 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appn8nn8n-node.js-

Explore more