CVE-2025-68613 is a critical Remote Code Execution (RCE) vulnerability affecting n8n, an open-source workflow automation platform, in versions prior to 1.120.4, 1.121.1, and 1.122.0. This flaw allows an authenticated attacker to execute arbitrary code with the privileges of the n8n process by exploiting insufficient isolation in the workflow expression evaluation system. With a CVSS score of 8.8 (High), the vulnerability has a low attack complexity and requires only low privileges, enabling full system compromise, unauthorized data access, and system-level operations. This RCE is actively exploited in the wild, listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, and public exploit modules are readily available. Users are strongly advised to upgrade to a patched version immediately, as temporary mitigations do not fully eliminate the risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.211.0, < 1.120.4CPE matchmatch criteria | cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:* | ||
1.121.0CPE matchmatch criteria | cpe:2.3:a:n8n:n8n:1.121.0:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.