n8n Webflow Trigger Vulnerability: What the Advisory Says
A plain-language look at the n8n Webflow Trigger vulnerability disclosed on GitHub on September 16, 2026, covering what changed, who is affected, and what to do now.

Checked against the cited sources on .
What Changed: The n8n Webflow Trigger Vulnerability
The n8n Webflow Trigger vulnerability, described in a GitHub security advisory identified as GHSA-hwv9-jhc7-f7c4, concerns a missing check in how the Webflow Trigger node validated incoming events. According to the advisory, the node accepted webhook requests without checking the x-webflow-signature HMAC that Webflow normally attaches to its event deliveries. That gap meant an unauthenticated attacker could send a forged request carrying fake, attacker-controlled data and have it trigger the workflow as though it had genuinely come from Webflow.
GitHub's advisory listing, published September 16, 2026, rated the issue Moderate severity, one of several n8n advisories posted the same day.
Sources: Missing Webhook Signature Verification in Webflow Trigger Node Allows Forged Event Injection · Advisory · n8n-io/n8n · GitHub, Security Advisories · n8n-io/n8n · GitHub
Who Is Affected: Versions Before the Patch and the n8n Webflow Trigger Security Advisory

According to the advisory, the fix applies to n8n instances running versions before 1.123.80, 2.39.6 and 2.40.1. n8n states the issue is fixed in these versions and instructs users to upgrade to one of them or later to remediate it. Any self-hosted instance on an older release, and any workflow that uses the Webflow Trigger node, falls within the scope the advisory describes.
| n8n release line | Patched version |
|---|---|
| 1.x branch | 1.123.80 |
| 2.x branch (2.39 series) | 2.39.6 |
| 2.x branch (2.40 series) | 2.40.1 |
The advisory also states that the signature-verification fix was applied to version 2 of the Webflow Trigger node specifically. n8n's own source code confirms the node is implemented as two separate versions, a version 1 class and a version 2 class, coexisting in the same node package.
Sources: Missing Webhook Signature Verification in Webflow Trigger Node Allows Forged Event Injection · Advisory · n8n-io/n8n · GitHub, n8n/packages/nodes-base/nodes/Webflow/WebflowTrigger.node.ts at master · n8n-io/n8n · GitHub
What the Fix Covers and What to Do Now
For most teams, resolving the n8n Webflow Trigger vulnerability comes down to running a patched release chosen from the version table above. The patch adds the webhook signature verification the node was missing, checking the x-webflow-signature header before a workflow runs. Checking your current version against the patched releases and upgrading is the most direct way to get the webhook signature verification n8n added in this patch, and this article prioritizes it based on the versions the advisory names.
If an immediate upgrade is not possible, the advisory itself recommends interim workarounds: deactivating unused Webflow Trigger workflows, restricting network access to Webflow's published IP ranges, and limiting n8n instance access to fully trusted users. The advisory states these measures do not fully remediate the risk and are meant only as short-term mitigation until you can upgrade.
This article calls this update the n8n webhook signature bypass fix, since it closes the specific gap the advisory reported. The checklist below separates the advisory's own instructions from suggestions this article adds for teams standardizing how they run n8n.
What the Advisory Doesn't Say
The advisory is silent on several points readers may want answered. It does not state whether n8n Cloud users need to take any action themselves, or whether cloud instances were already upgraded automatically; this is simply not addressed in the published text. The advisory also records no known CVE ID for this n8n Webflow Trigger vulnerability at the time of publication.
Separately from this advisory, Cornelius Suermann, n8n's VP of Engineering, has written on the n8n Blog about how the company approaches vulnerability disclosure in general terms. His post does not describe this particular advisory, but it explains why an absence of headline-grabbing reports is not, by itself, reassuring:
The advisory likewise does not clarify whether Webflow Trigger node version 1 remains vulnerable after an instance upgrade, or how to migrate an existing workflow from version 1 to version 2. Readers who rely on this node should treat that gap as unresolved rather than assume either answer.
Background: What the Webflow Trigger Node Does
For context, n8n's own documentation describes Webflow as a browser-based website-building platform, and the Webflow Trigger node as the way an n8n workflow listens for events from a connected Webflow site, such as form submissions or content changes. This description covers the node's general purpose and makes no mention of the vulnerability, the affected versions, or the fix; it is background only.
Sources: Webflow Trigger | Nodes | n8n Docs


