{"id":"CVE-2025-68949","aliases":["GHSA-w96v-gf22-crwp"],"url":"https://o3.security/vulnerability/CVE-2025-68949","summary":"n8n has a Webhook Node IP Whitelist Bypass via Partial String Matching","details":"n8n is an open source workflow automation platform. From 1.36.0 to before 2.2.0, the Webhook node’s IP whitelist validation performed partial string matching instead of exact IP comparison. As a result, an incoming request could be accepted if the source IP address merely contained the configured whitelist entry as a substring. This issue affected instances where workflow editors relied on IP-based access controls to restrict webhook access. Both IPv4 and IPv6 addresses were impacted. An attacker with a non-whitelisted IP could bypass restrictions if their IP shared a partial prefix with a trusted address, undermining the intended security boundary. This vulnerability is fixed in 2.2.0.","published":"2026-01-13T18:43:20.189Z","modified":"2026-08-12T03:51:12.657983873Z","cvss":{"score":5.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"},"epss":{"score":0.00293,"percentile":0.22038,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"n8n","fixedVersion":"2.2.0"}],"fix":{"url":"https://github.com/n8n-io/n8n/commit/11f8597d4ad69ea3b58941573997fdbc4de1fec5","label":"n8n-io/n8n@11f8597"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/68xxx/CVE-2025-68949.json"},{"type":"ADVISORY","url":"https://github.com/n8n-io/n8n/security/advisories/GHSA-w96v-gf22-crwp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-68949"},{"type":"REPORT","url":"https://github.com/n8n-io/n8n/issues/23399"},{"type":"FIX","url":"https://github.com/n8n-io/n8n/commit/11f8597d4ad69ea3b58941573997fdbc4de1fec5"},{"type":"FIX","url":"https://github.com/n8n-io/n8n/pull/23399"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:12.657983873Z"}}