CVE-2025-68613
n8n Vulnerable to Remote Code Execution via Expression Injection
Exploited in the wild. In CISA KEV since 2026‑03‑11. A vendor fix is available.
What to do
The vendor has published a fix. Version details are below where the sources state them.
Steps
Written by AI from the record- Check your n8n version and whether you are running a version prior to 1.120.4, 1.121.1, or 1.122.0.
- If you’re affected, upgrade n8n to a fixed release immediately: 1.120.4, 1.121.1, or 1.122.0.
- If you can’t upgrade right away, restrict workflow creation/editing to only fully trusted users and reduce server privileges/network exposure for the n8n host until the upgrade is done.
- After updating, review recent workflow changes and user activity for anything unusual and keep access to n8n tightly controlled.
What it is
From the CVE record
n8n is an open source workflow automation platform. Versions starting with 0.211.0 and prior to 1.120.4, 1.121.1, and 1.122.0 contain a critical Remote Code Execution (RCE) vulnerability in their workflow expression evaluation system. Under certain conditions, expressions supplied by authenticated users during workflow configuration may be evaluated in an execution context that is not sufficiently isolated from the underlying runtime. An authenticated attacker could abuse this behavior to execute arbitrary code with the privileges of the n8n process. Successful exploitation may lead to full compromise of the affected instance, including unauthorized access to sensitive data, modification of workflows, and execution of system-level operations. This issue has been fixed in versions 1.120.4, 1.121.1, and 1.122.0. Users are strongly advised to upgrade to a patched version, which introduces additional safeguards to restrict expression evaluation. If upgrading is not immediately possible, administrators should consider the following temporary mitigations: Limit workflow creation and editing permissions to fully trusted users only; and/or deploy n8n in a hardened environment with restricted operating system privileges and network access to reduce the impact of potential exploitation. These workarounds do not fully eliminate the risk and should only be used as short-term measures.
In plain language
Written by AI from the recordIf you use n8n, a malicious authenticated user can inject code into a workflow and take over the server running n8n—this is serious and RED, so you should upgrade right away if you’re on the affected versions.
n8n has an authenticated expression-injection flaw that can be used to execute arbitrary code on the n8n server (remote code execution) when a user creates/edits workflows and malicious expressions are evaluated in an insufficiently isolated execution context; exploitation is confirmed by CISA KEV.
If you're affected
- Full takeover of the n8n server
- Sensitive workflow and data theft
- Workflow manipulation and persistence
- Business disruption and downtime
Exploitation
Where each signal puts this CVE on the scale from published to confirmed exploited.
- CISA KEV
Listed as exploited in the wild since 2026-03-11.
US federal agencies must remediate by 2026-03-25.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Public exploits
No public exploit or proof of concept found in the sources we track.
- EPSS
99% chance of exploitation activity in the next 30 days, which ranks it in the 99th percentile of scored CVEs.
Exploit Prediction Scoring System, FIRST.org. A probability, not a confirmation.
Lifecycle
9 events over 188 days, from the signal feeds we watch.
- OpenVAS check added
- EPSS band changehigh → critical
- Added to CISA KEV
- Nuclei check added
- Patch availablerecord updated
- Publishedweakness classified, att&ck mapped
Affected products
Technical detail
CVSS 3.1 vector
Open in the CVSS calculatorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Scored 9.9 by NVD.
How it is reached
- Attack Vector NetworkExploitable remotely over the network without any special conditions
- Attack Complexity LowNo special conditions — the attack can be reliably reproduced
- Privileges Required LowRequires basic user-level privileges
- User Interaction NoneNo user interaction needed — fully automated exploitation
Scope
- Scope ChangedThe exploit can affect other components (e.g. sandbox escape, host compromise from VM)
Impact if exploited
- Confidentiality HighTotal information disclosure — all data in the component is compromised
- Integrity HighTotal loss of integrity — attacker can modify any data in the component
- Availability HighTotal denial of service — the component is completely unavailable
Weaknesses
ATT&CK techniques
Mapped from the weaknesses above (CWE to ATT&CK), not observed in attacks.
Sources
References in the record
- github.com/n8n-io/n8n/commit/08f332015153decdda3c37ad4fcb9f7ba13a7c79&
- github.com/n8n-io/n8n/commit/1c933358acef527ff61466e53268b41a04be1000&
- github.com/n8n-io/n8n/commit/39a2d1d60edde89674ca96dcbb3eb076ffff6316&
And 10 more references. See all after sign-in
In the news
- Leaked n8n API Tokens Exposed Live Instances to Credential Theft
- Китайский хакер использовал DeepSeek для проведения автономных атак
- Chinese hacker used DeepSeek to launch autonomous cyberattacks on vulnerable servers
- Hacker uses DeepSeek AI to autonomously attack vulnerable servers
- Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks
- ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories
- Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks
- Iran-Linked Hackers Use New Cavern C2 Framework to Target Israeli Organizations
Watch the software you run.
My Stack ranks new CVEs for your products by real-world exploitation, so the next exploited one reaches you without reading every advisory.
We'll flag the next CVE, public exploit or patch for N8n, not every advisory. This one: actively exploited.
A free account adds
- The full version matrix and every affected product
- Exploit links, proofs of concept and Metasploit modules
- Email alerts for the products you watch
- The same data over REST API, MCP and CLI