Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4305 articles · 196683 vulns · 37/41 feeds (7d)
← Back to list
9.9
CVE-2025-68613KEVEXPLOITEDPATCHED
n8n · n8n

n8n is an open source workflow automation platform. Versions starting with 0.211.0 and prior to 1.120.4, 1.121.1, and 1.122.0 contain a critical Remote Code Execution (RCE) vulnerability in their work

Description

n8n is an open source workflow automation platform. Versions starting with 0.211.0 and prior to 1.120.4, 1.121.1, and 1.122.0 contain a critical Remote Code Execution (RCE) vulnerability in their workflow expression evaluation system. Under certain conditions, expressions supplied by authenticated users during workflow configuration may be evaluated in an execution context that is not sufficiently isolated from the underlying runtime. An authenticated attacker could abuse this behavior to execute arbitrary code with the privileges of the n8n process. Successful exploitation may lead to full compromise of the affected instance, including unauthorized access to sensitive data, modification of workflows, and execution of system-level operations. This issue has been fixed in versions 1.120.4, 1.121.1, and 1.122.0. Users are strongly advised to upgrade to a patched version, which introduces additional safeguards to restrict expression evaluation. If upgrading is not immediately possible, administrators should consider the following temporary mitigations: Limit workflow creation and editing permissions to fully trusted users only; and/or deploy n8n in a hardened environment with restricted operating system privileges and network access to reduce the impact of potential exploitation. These workarounds do not fully eliminate the risk and should only be used as short-term measures.

Affected Products

VendorProductVersions
n8nn8n< 1.120.4

References

  • https://github.com/n8n-io/n8n/commit/08f332015153decdda3c37ad4fcb9f7ba13a7c79(Patch)
  • https://github.com/n8n-io/n8n/commit/1c933358acef527ff61466e53268b41a04be1000(Patch)
  • https://github.com/n8n-io/n8n/commit/39a2d1d60edde89674ca96dcbb3eb076ffff6316(Patch)
  • https://github.com/n8n-io/n8n/security/advisories/GHSA-v98v-ff95-f3cp(Patch, Vendor Advisory)
  • https://www.akamai.com/blog/security-research/2026/feb/zerobot-malware-targets-n8n-automation-platform(Exploit, Third Party Advisory)
  • https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-68613(US Government Resource)
  • https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-68613.yaml(exploit, nuclei)

Related News (7 articles)

Tier D
The Hacker News19d ago
Leaked n8n API Tokens Exposed Live Instances to Credential Theft
→ No new info (linked only)
Tier D
Help Net Security21d ago
Chinese hacker used DeepSeek to launch autonomous cyberattacks on vulnerable servers
→ No new info (linked only)
Tier D
BleepingComputer24d ago
Hacker uses DeepSeek AI to autonomously attack vulnerable servers
→ No new info (linked only)
Tier D
Infosecurity Magazine24d ago
Chinese Hacker Uses DeepSeek AI to Orchestrate Vulnerability Exploits
→ No new info (linked only)
Tier D
The Hacker News24d ago
Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks
→ No new info (linked only)
Tier D
The Hacker News49d ago
Iran-Linked Hackers Use New Cavern C2 Framework to Target Israeli Organizations
→ No new info (linked only)
Tier D
The Hacker News139d ago
Over 1,000 Exposed ComfyUI Instances Targeted in Cryptomining Botnet Campaign
→ No new info (linked only)
CVSS 3.19.9 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
1.120.4
CWECWE-913, CWE-913
PublishedDec 19, 2025
Last enriched145d ago
Trending Score7
Source articles7
Independent4
Info Completeness11/14
Missing: epss, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

MEDIUMCVE-2026-59259EXP
n8n - Permission Bypass via Expression Parser Mismatch in External Secrets
MEDIUMCVE-2026-59253
n8n - Improper Authorization in Workflow Assignment to Folders
MEDIUMCVE-2026-58661
n8n - Disk Space Exhaustion via Data-Table File Upload Endpoint
MEDIUMCVE-2026-59254EXP
n8n - External Secrets Disclosure via Workflow Node Expressions
NONECVE-2026-56354EXP
n8n - Cross-Site Scripting and Open Redirect in Form Node

Pin to Dashboard

Verification

State: verified
Confidence: 100%

Vulnerability Timeline

CVE Published
Dec 19, 2025
Added to CISA KEV
Dec 19, 2025
Actively Exploited
Mar 11, 2026
Exploit Available
Mar 11, 2026
Patch Available
Mar 11, 2026
Discovered by ZDM
Apr 1, 2026