Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-68613

99
FAUCET Score

CVE-2025-68613 is a critical Remote Code Execution (RCE) vulnerability affecting n8n, an open-source workflow automation platform, in versions prior to 1.120.4, 1.121.1, and 1.122.0. This flaw allows an authenticated attacker to execute arbitrary code with the privileges of the n8n process by exploiting insufficient isolation in the workflow expression evaluation system. With a CVSS score of 8.8 (High), the vulnerability has a low attack complexity and requires only low privileges, enabling full system compromise, unauthorized data access, and system-level operations. This RCE is actively exploited in the wild, listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, and public exploit modules are readily available. Users are strongly advised to upgrade to a patched version immediately, as temporary mitigations do not fully eliminate the risk.

Impacted Technologies

VendorProductVersion(s)CPE
>= 0.211.0, < 1.120.4CPE matchmatch criteria
cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*
1.121.0CPE matchmatch criteria
cpe:2.3:a:n8n:n8n:1.121.0:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 3.1

9.9CRITICAL

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.1
Impact Score
6.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
97.88%
Probability of exploitation in next 30 days
EPSS Percentile
99.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
Added to KEV · Mar 11, 2026
Metasploit: n8n Workflow Expression Remote Code Execution · Jun 10, 2025
Nuclei: CVE-2025-68613 · Dec 25, 2025
This CVE's current EPSS score of 0.9788 is in the 100th percentile among its peer group of 17,823 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

github_advisorypatch availablevia nvd_reference
View patch
npmpatch availablevia ghsa
Product: n8nFixed in: 1.120.4
npmpatch availablevia ghsa
Product: n8nFixed in: 1.121.1

Vendor Advisories (1)

npmGHSA-v98v-ff95-f3cpcritical

n8n Vulnerable to Remote Code Execution via Expression Injection

Dec 22, 2025

References

akamai.com / blog/security-research/2026/feb/zerobot-malware-targets-n8n-automation-platform
ExploitThird Party Advisory
cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
github.com / n8n-io/n8n/commit/08f332015153decdda3c37ad4fcb9f7ba13a7c79
Patch
github.com / n8n-io/n8n/commit/1c933358acef527ff61466e53268b41a04be1000
Patch
github.com / n8n-io/n8n/commit/39a2d1d60edde89674ca96dcbb3eb076ffff6316
Patch
github.com / n8n-io/n8n/security/advisories/GHSA-v98v-ff95-f3cp
PatchVendor Advisory