Vulnerability record · CVE-2025-68613 · published 19 December 2025
CVE-2025-68613: n8n workflow expression evaluation RCE for authenticated users
N8n · N8n
n8n versions from 0.211.0 before 1.120.4, 1.121.1, and 1.122.0 evaluate user-supplied workflow expressions in an execution context that is not sufficiently isolated from the underlying runtime. An authenticated user who can create or edit workflows can therefore execute arbitrary code as the n8n process. Because n8n commonly holds credentials and integrations, compromise of the instance exposes sensitive data and connected systems.
Description
n8n is an open source workflow automation platform. Versions starting with 0.211.0 and prior to 1.120.4, 1.121.1, and 1.122.0 contain a critical Remote Code Execution (RCE) vulnerability in their workflow expression evaluation system. Under certain conditions, expressions supplied by authenticated users during workflow configuration may be evaluated in an execution context that is not sufficiently isolated from the underlying runtime. An authenticated attacker could abuse this behavior to execute arbitrary code with the privileges of the n8n process. Successful exploitation may lead to full compromise of the affected instance, including unauthorized access to sensitive data, modification of workflows, and execution of system-level operations. This issue has been fixed in versions 1.120.4, 1.121.1, and 1.122.0. Users are strongly advised to upgrade to a patched version, which introduces additional safeguards to restrict expression evaluation. If upgrading is not immediately possible, administrators should consider the following temporary mitigations: Limit workflow creation and editing permissions to fully trusted users only; and/or deploy n8n in a hardened environment with restricted operating system privileges and network access to reduce the impact of potential exploitation. These workarounds do not fully eliminate the risk and should only be used as short-term measures.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityRemote code execution with low attack complexity, active exploitation per KEV and third-party reporting, and an EPSS probability above 0.99 make this an urgent patch.
What it is
n8n versions from 0.211.0 before 1.120.4, 1.121.1, and 1.122.0 evaluate user-supplied workflow expressions in an execution context that is not sufficiently isolated from the underlying runtime. An authenticated user who can create or edit workflows can therefore execute arbitrary code as the n8n process. Because n8n commonly holds credentials and integrations, compromise of the instance exposes sensitive data and connected systems.
Impact
An attacker with a valid account gains remote code execution with the privileges of the n8n process, leading to full instance compromise: theft of stored credentials and data, workflow tampering, and system-level operations on the host.
Attack surface
Reached over the network through the workflow expression evaluation feature; the CVSS vector (AV:N/AC:L/PR:L/UI:N) indicates low complexity, required low-privileged authentication, and no user interaction. Only users permitted to create or edit workflows can supply the malicious expression.
Exploitation
CISA added this to KEV on 2026-03-11 with a 2026-03-25 remediation due date, and EPSS is 0.99105 (99.9th percentile). A third-party advisory reference is tagged Exploit and describes Zerobot malware targeting n8n, indicating active exploitation in the wild.
What to do
- Upgrade to n8n 1.120.4, 1.121.1, or 1.122.0, which add safeguards restricting expression evaluation.
- If immediate upgrade is impossible, restrict workflow creation and editing permissions to fully trusted users only.
- Run n8n with least-privilege OS accounts and restrict its network access to reduce blast radius.
- Rotate credentials and secrets stored in n8n after any suspected compromise, since the process can read them.
- Treat internet-exposed n8n instances as urgent: apply the vendor fix or take them offline until patched.
Detection
- Audit n8n logs for workflow creation or edits by unexpected accounts, especially expressions containing code-like or system-call patterns.
- Monitor the n8n process for child processes, shell execution, or outbound connections that do not match normal workflow behavior.
- Alert on new or modified workflows that invoke expression evaluation shortly after account creation or privilege changes.
- Hunt for indicators associated with Zerobot malware on hosts running n8n, per the referenced third-party research.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-68613 to the Known Exploited Vulnerabilities catalog on 11 March 2026 as "n8n Improper Control of Dynamically-Managed Code Resources Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 25 March 2026.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2025-68613 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-68613), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.