CVE-2026-54308: n8n: Missing Token Validation on Microsoft Agent 365 Trigger and Stripe Nodes
The MicrosoftAgent365Trigger and StripeTrigger node did not validate that inbound requests. As a result, an unauthenticated attacker who knows the webhook URL could submit a forged payload and cause the workflow to execute with attacker-controlled data.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-54308 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →