Threat Intelligence / CVE / CVE-2026-54308

CVE-2026-54308

CVSS 6.3 · EPSS 0.4% · Priority 4.5/10 · Published 2026-06-23

As of 2026-06-24, CVE-2026-54308 is a CVSS 6.3 vulnerability. EPSS exploitation probability 0.4%. Threadlinqs Intelligence tracks 0 threats exploiting it.

Last updated: 2026-06-24

n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, the MicrosoftAgent365Trigger and StripeTrigger node did not validate that inbound requests. As a result, an unauthenticated attacker who knows the webhook URL could submit a forged payload and cause the workflow to execute with attacker-controlled data. This vulnerability is fixed in 2.25.7 and 2.26.2.

Weaknesses (CWE)

CWE-290

Affected packages

References

Full detection coverage & IOCs for threats exploiting CVE-2026-54308 are available via the Threadlinqs MCP server (Purple tier). View plans →

← all vulnerabilities · Markdown version · Threadlinqs Intelligence

Enriched from CVE.org, NVD (this product uses the NVD API but is not endorsed or certified by the NVD), FIRST EPSS, CISA KEV, and GitHub Security Advisories.