s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

CVE-2025-68613

📛 CVE Title

n8n Vulnerable to Remote Code Execution via Expression Injection

Description

n8n is an open source workflow automation platform. Versions starting with 0.211.0 and prior to 1.120.4, 1.121.1, and 1.122.0 contain a critical Remote Code Execution (RCE) vulnerability in their workflow expression evaluation system. Under certain conditions, expressions supplied by authenticated users during workflow configuration may be evaluated in an execution context that is not sufficiently isolated from the underlying runtime. An authenticated attacker could abuse this behavior to execute arbitrary code with the privileges of the n8n process. Successful exploitation may lead to full compromise of the affected instance, including unauthorized access to sensitive data, modification of workflows, and execution of system-level operations. This issue has been fixed in versions 1.120.4, 1.121.1, and 1.122.0. Users are strongly advised to upgrade to a patched version, which introduces additional safeguards to restrict expression evaluation. If upgrading is not immediately possible, administrators should consider the following temporary mitigations: Limit workflow creation and editing permissions to fully trusted users only; and/or deploy n8n in a hardened environment with restricted operating system privileges and network access to reduce the impact of potential exploitation. These workarounds do not fully eliminate the risk and should only be used as short-term measures.

Overview

State
PUBLISHED
Assigner (CNA)
GitHub_M
CVSS severity
CRITICAL
CVSS score
CVSS 10.0 / 10 10.0 10.0 / 10
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Effective score
10.0 / 10 CRITICAL source: CNA overview
CWE(s)
CWE-913
Reserved
2025-12-19
Published
2025-12-19 22:23 UTC
Last updated
2026-03-12 03:55 UTC
Source
https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2025/68xxx/CVE-2025-68613.json
Linked Threat
CVE-2025-68613 — n8n n8n: n8n Improper Control of Dynamically-Managed Code Resources Vulnerability

CISA Known Exploited Vulnerabilities CISA KEV

CISA has confirmed in-the-wild exploitation of this CVE. Federal agencies must remediate by the due date below; private orgs should treat it as priority-1.

Vulnerability name
n8n Improper Control of Dynamically-Managed Code Resources Vulnerability
Vendor / project
n8n
Product
n8n
Date added to KEV
2026-03-11
Remediation due
2026-03-25
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Ransomware campaign use
Unknown
CISA notes
https://github.com/n8n-io/n8n/security/advisories/GHSA-v98v-ff95-f3cp ; https://nvd.nist.gov/vuln/detail/CVE-2025-68613
CISA listing
www.cisa.gov/known-exploited-vulnerabilities-catalog

NVD triage scoring NVD CVE 2.0

Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.

NVD published
2025-12-19 23:15:52 UTC
NVD last modified
2026-03-11 19:40:09 UTC
NVD CVSS v3.1
CVSS 9.9 / 10 9.9 9.9 / 10 CRITICAL source: security-advisories@github.com
NVD CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Exploitability subscore
3.1 / 10
Impact subscore
6.0 / 10
EPSS score
0.6576 (probability of exploitation in next 30 days)
EPSS percentile
98.53% vs all CVEs — higher = more likely to be exploited, as of 2026-05-24

NVD / KEV / EPSS data refreshed 2026-05-25 04:51 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.

European Union Vulnerability Database ENISA EUVD

ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.

EUVD ID
EUVD-2025-204618
Assigner
GitHub_M
Published
Dec 19, 2025, 10:23:47 PM
Updated
Mar 12, 2026, 3:55:15 AM
EUVD base score (CVSS 3.1)
10.0 / 10
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EUVD-reported EPSS
65.7600
Vendors
n8n-io
Products
n8n (0.211.0, < 1.120.4)
n8n (= 1.121.0)
Aliases
GHSA-v98v-ff95-f3cp

ENISA description: n8n is an open source workflow automation platform. Versions starting with 0.211.0 and prior to 1.120.4, 1.121.1, and 1.122.0 contain a critical Remote Code Execution (RCE) vulnerability in their workflow expression evaluation system. Under certain conditions, expressions supplied by authenticated users during workflow configuration may be evaluated in an execution context that is not sufficiently isolated from the underlying runtime. An authenticated attacker could abuse this behavior to execute arbitrary code with the privileges of the n8n process. Successful exploitation may lead to full compromise of the affected instance, including unauthorized access to sensitive data, modification of workflows, and execution of system-level operations. This issue has been fixed in versions 1.120.4, 1.121.1, and 1.122.0. Users are strongly advised to upgrade to a patched version, which introduces additional safeguards to restrict expression evaluation. If upgrading is not immediately possible, administrators should consider the following temporary mitigations: Limit workflow creation and editing permissions to fully trusted users only; and/or deploy n8n in a hardened environment with restricted operating system privileges and network access to reduce the impact of potential exploitation. These workarounds do not fully eliminate the risk and should only be used as short-term measures.

EUVD references (4)

Affected products (1)

VendorProductVersionsPlatforms
n8n-io n8n >= 0.211.0, < 1.120.4 (affected), = 1.121.0 (affected)

Affected products — CPE 2.3 (2) NVD

NVD's normalized CPE 2.3 matchers, used by vendor tools (vulnerability scanners, asset managers) for automated detection. Compare with the CNA's free-text "Affected products" section above.

  • cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*
  • cpe:2.3:a:n8n:n8n:1.121.0:*:*:*:*:node.js:*:*

Vendor references (4)

References embedded in the original CVE record by the assigning CNA.

MITRE references (4) cveawg.mitre.org

Pulled from MITRE's CVE Services API by the 🛰 Backfill from MITRE button.

Web references (4)

DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.

NVD-tagged references (6)

Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.

Indicators (2)

IOCs linked to the auto-promoted Threat row.

TypeValueVirusTotalAttached
cve CVE-2025-68613 no local data 2026-05-14 02:58 UTC
cwe CWE-913 no local data 2026-05-14 02:58 UTC

Flagged vendors

    Remediations (9)

    Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.

    • web:www.tenable.com

      n8n is an open source workflow automation platform. Versions starting with 0.211.0 and prior to 1.120.4, 1.121.1, and 1.122.0 contain a critical Remote Code Execution (RCE) vulnerability in their workflow expression evaluation system. Under certain conditions, expressions supplied by authenticated users during workflow configuration may be evaluated in an execution context that is not ...

      2026-05-14 02:59 UTC
    • web:nvd.nist.gov

      Secure .gov websites use HTTPS A lock () or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

      2026-05-14 02:59 UTC
    • web:stack.watch

      CVE-2025-68613 Published on December 19, 2025 n8n Vulnerable to Remote Code Execution via Expression Injection n8n is an open source workflow automation platform. Versions starting with 0.211.0 and prior to 1.120.4, 1.121.1, and 1.122.0 contain a critical Remote Code Execution (RCE) vulnerability in their workflow expression evaluation system.

      2026-05-14 02:59 UTC
    • web:www.appsecure.security

      Mitigation & Remediation Organizations must implement the following measures to mitigate the risk associated with CVE-2025-68613 : upgrade to the patched versions 1.120.4, 1.121.1, or 1.122.0. If immediate upgrading is not possible, limit workflow creation and editing permissions to fully trusted users, and deploy n8n in a hardened environment with restricted operating system privileges.

      2026-05-14 02:59 UTC
    • web:www.bleepingcomputer.com

      The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered government agencies on Wednesday to patch their systems against an actively exploited n8n vulnerability.

      2026-05-14 02:59 UTC
    • web:advisories.gitlab.com

      CVE-2025-68613 n8n Vulnerable to Remote Code Execution via Expression Injection: n8n contains a critical Remote Code Execution (RCE) vulnerability in its workflow expression evaluation system.

      2026-05-14 02:59 UTC
    • web:www.cve.news

      Conclusion CVE-2025-68613 is a serious security flaw that cuts straight to the core of server-side workflow automation security. If you run n8n, patching this vulnerability is urgent — don't leave your server exposed to attackers who could take full control of your systems. Key takeaways: Harden your deployment until you can patch fully.

      2026-05-14 02:59 UTC
    • web:www.sentinelone.com

      CVE-2025-68613 is a remote code execution vulnerability in N8n workflow automation. Learn about its impact, affected versions, and mitigation methods.

      2026-05-14 02:59 UTC
    • CISA KEV

      Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Due date: 2026-03-25 Known ransomware campaign use: Unknown

      2026-05-14 01:13 UTC

    AI Forensic Analysis

    Only Available for Registered Users. Sign in to view.

    Raw JSON

    The full cvelistV5 record. Download as CVE-2025-68613.json.

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-68613",
                    "options": [
                      {
                        "Exploitation": "active"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-03-03T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              },
              {
                "other": {
                  "content": {
                    "dateAdded": "2026-03-11",
                    "reference": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-68613"
                  },
                  "type": "kev"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-03-12T03:55:15.270Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "third-party-advisory"
                ],
                "url": "https://www.akamai.com/blog/security-research/2026/feb/zerobot-malware-targets-n8n-automation-platform"
              },
              {
                "tags": [
                  "government-resource"
                ],
                "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-68613"
              }
            ],
            "timeline": [
              {
                "lang": "en",
                "time": "2026-03-11T00:00:00.000Z",
                "value": "CVE-2025-68613 added to CISA KEV"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n8n",
              "vendor": "n8n-io",
              "versions": [
                {
                  "status": "affected",
                  "version": ">= 0.211.0, < 1.120.4"
                },
                {
                  "status": "affected",
                  "version": "= 1.121.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "n8n is an open source workflow automation platform. Versions starting with 0.211.0 and prior to 1.120.4, 1.121.1, and 1.122.0 contain a critical Remote Code Execution (RCE) vulnerability in their workflow expression evaluation system. Under certain conditions, expressions supplied by authenticated users during workflow configuration may be evaluated in an execution context that is not sufficiently isolated from the underlying runtime. An authenticated attacker could abuse this behavior to execute arbitrary code with the privileges of the n8n process. Successful exploitation may lead to full compromise of the affected instance, including unauthorized access to sensitive data, modification of workflows, and execution of system-level operations. This issue has been fixed in versions 1.120.4, 1.121.1, and 1.122.0. Users are strongly advised to upgrade to a patched version, which introduces additional safeguards to restrict expression evaluation. If upgrading is not immediately possible, administrators should consider the following temporary mitigations: Limit workflow creation and editing permissions to fully trusted users only; and/or deploy n8n in a hardened environment with restricted operating system privileges and network access to reduce the impact of potential exploitation. These workarounds do not fully eliminate the risk and should only be used as short-term measures."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 10,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-913",
                  "description": "CWE-913: Improper Control of Dynamically-Managed Code Resources",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-12-19T22:23:47.777Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/n8n-io/n8n/security/advisories/GHSA-v98v-ff95-f3cp",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/n8n-io/n8n/security/advisories/GHSA-v98v-ff95-f3cp"
            },
            {
              "name": "https://github.com/n8n-io/n8n/commit/08f332015153decdda3c37ad4fcb9f7ba13a7c79",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/n8n-io/n8n/commit/08f332015153decdda3c37ad4fcb9f7ba13a7c79"
            },
            {
              "name": "https://github.com/n8n-io/n8n/commit/1c933358acef527ff61466e53268b41a04be1000",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/n8n-io/n8n/commit/1c933358acef527ff61466e53268b41a04be1000"
            },
            {
              "name": "https://github.com/n8n-io/n8n/commit/39a2d1d60edde89674ca96dcbb3eb076ffff6316",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/n8n-io/n8n/commit/39a2d1d60edde89674ca96dcbb3eb076ffff6316"
            }
          ],
          "source": {
            "advisory": "GHSA-v98v-ff95-f3cp",
            "discovery": "UNKNOWN"
          },
          "title": "n8n Vulnerable to Remote Code Execution via Expression Injection"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2025-68613",
        "datePublished": "2025-12-19T22:23:47.777Z",
        "dateReserved": "2025-12-19T14:58:47.823Z",
        "dateUpdated": "2026-03-12T03:55:15.270Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }