
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21894 is an authentication bypass vulnerability in the n8n workflow automation platform's Stripe Trigger node, titled "Missing Stripe-Signature Verification Allows Unauthenticated Forged Webhooks." The flaw affects n8n versions >= 0.150.0 and < 2.2.2 (npm package). It was disclosed on January 7, 2026 via a GitHub Security Advisory published by n8n maintainer csuermann, and subsequently published to the NVD on January 8, 2026. The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory, n8n Security Advisory).
The root cause is classified as CWE-290 (Authentication Bypass by Spoofing). The Stripe Trigger node correctly creates and stores a Stripe webhook signing secret upon registering the webhook endpoint, but the incoming webhook request handler never validated the Stripe-Signature header against that stored secret. As a result, any unauthenticated HTTP client that knows the webhook URL could send a crafted POST request with a matching Stripe event type (e.g., charge.succeeded, customer.subscription.updated) and cause the workflow to execute as if a legitimate Stripe event had been received. The fix, introduced in PR #22764, adds a verifySignature helper that parses the Stripe-Signature header, validates the HMAC-SHA256 signature using the stored secret, and enforces a 300-second timestamp tolerance window to prevent replay attacks (n8n Security Advisory, Patch Commit).
Successful exploitation allows an unauthenticated attacker to trigger arbitrary n8n workflows that use the Stripe Trigger node by forging payment or subscription events (e.g., faking a successful payment, a subscription upgrade, or a refund). This primarily affects workflow integrity — downstream business logic such as order fulfillment, account provisioning, or subscription management could be manipulated without any legitimate Stripe transaction occurring. Confidentiality impact is low (the attacker may observe workflow execution responses), and there is no direct availability impact. The practical risk is partially mitigated by the high-entropy UUID embedded in the webhook URL, though authenticated n8n users with workflow access can view this ID (n8n Security Advisory).
No public proof-of-concept exploit code has been identified, and there is no evidence of in-the-wild exploitation at this time (GitHub Advisory). The EPSS score is approximately 0.023% (7th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires knowledge of the webhook URL (which contains a high-entropy UUID), raising the effective attack complexity, though insider threat or information leakage scenarios could expose this URL.
https://<n8n-host>/webhook/<UUID> where the UUID is unique per workflow. An insider or compromised n8n account can retrieve this from the workflow editor.{"type": "charge.succeeded", "id": "ch_fake123", ...}).curl) to POST the crafted payload to the webhook URL without any Stripe-Signature header — the vulnerable node does not validate it: curl -X POST https://<n8n-host>/webhook/<UUID> -H 'Content-Type: application/json' -d '{"type":"charge.succeeded",...}'./webhook/<UUID>) originating from non-Stripe IP ranges (Stripe's webhook IPs are documented and can be allowlisted); requests lacking a Stripe-Signature header or with a malformed one.Upgrade n8n to version 2.2.2 or later, which adds proper HMAC-SHA256 Stripe-Signature header verification with a 5-minute timestamp tolerance window. If immediate upgrade is not possible, deactivate all workflows using the Stripe Trigger node, or restrict access to those workflows to trusted users only to prevent webhook URL exposure. Additionally, configure a Stripe webhook signing secret in the n8n Stripe API credentials after upgrading, as the fix only enforces verification when a secret is configured. Network-level controls (e.g., allowlisting Stripe's published IP ranges at the firewall) can further reduce exposure (n8n Security Advisory, PR #22764).
The vulnerability was credited to security researchers nkoorty and jjjutla, with geckosecurity listed as the tool used for discovery, and a technical write-up was published by Gecko Security (Gecko Security Blog). A Reddit thread in r/bugbounty discussed the vulnerability, and a blog post on infinitsec.net provided additional coverage. Community reaction has been relatively muted given the moderate severity and absence of active exploitation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."