CVE-2025-68613Active Exploitation(n8n / n8n)

CRITICALCVSS 8.8 · HIGHCISA KEV

Exploitation observed; activity peaked at 23 mentions and remains active

Immediate actions

  • Patch n8n n8n systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

n8n is an open source workflow automation platform. Versions starting with 0.211.0 and prior to 1.120.4, 1.121.1, and 1.122.0 contain a critical Remote Code Execution (RCE) vulnerability in their workflow expression evaluation system. Under certain conditions, expressions supplied by authenticated users during workflow configuration may be evaluated in an execution context that is not sufficiently isolated from the underlying runtime. An authenticated attacker could abuse this behavior to execute arbitrary code with the privileges of the n8n process. Successful exploitation may lead to full compromise of the affected instance, including unauthorized access to sensitive data, modification of workflows, and execution of system-level operations. This issue has been fixed in versions 1.120.4, 1.121.1, and 1.122.0. Users are strongly advised to upgrade to a patched version, which introduces additional safeguards to restrict expression evaluation. If upgrading is not immediately possible, administrators should consider the following temporary mitigations: Limit workflow creation and editing permissions to fully trusted users only; and/or deploy n8n in a hardened environment with restricted operating system privileges and network access to reduce the impact of potential exploitation. These workarounds do not fully eliminate the risk and should only be used as short-term measures.

8.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-03-25. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-913

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • n8n

Threat summary

  • Active exploitation appears in 61 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 112 mentions across 40 observed days

What's happening

  • Active exploitation reported across 61 signals
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 11 signals
  • Patch or workaround mentioned in 42 signals
  • Technical details provided in 75 signals
  • Disclosure: 17 classified signals
  • General: 15 classified signals
  • Peaked 23d ago at 23 mentions (2026-03-12); latest day: 1
  • 112 total mentions across 40 days

Affected systems

Vendors
Products
n8n

1 version affected across 1 product

Deep dive

Activity timeline112 mentions / 40d
06121723Mentions · 2026-01-27: 1Mentions · 2026-01-28: 2Mentions · 2026-01-31: 1Mentions · 2026-02-04: 3Mentions · 2026-02-05: 5Mentions · 2026-02-06: 2Mentions · 2026-02-11: 1Mentions · 2026-02-13: 1Mentions · 2026-02-28: 1Mentions · 2026-03-01: 1Mentions · 2026-03-03: 3Mentions · 2026-03-04: 3Mentions · 2026-03-05: 1Mentions · 2026-03-06: 1Mentions · 2026-03-08: 1Mentions · 2026-03-11: 6Mentions · 2026-03-12: 23Mentions · 2026-03-13: 15Mentions · 2026-03-14: 6Mentions · 2026-03-15: 1Mentions · 2026-03-16: 5Mentions · 2026-03-17: 2Mentions · 2026-03-19: 4Mentions · 2026-03-20: 2Mentions · 2026-03-23: 2Mentions · 2026-03-24: 1Mentions · 2026-03-25: 3Mentions · 2026-03-30: 2Mentions · 2026-04-06: 1Mentions · 2026-05-26: 1Mentions · 2026-06-13: 1Mentions · 2026-06-30: 1Mentions · 2026-07-12: 1Mentions · 2026-08-02: 1Mentions · 2026-08-04: 1Mentions · 2026-08-05: 1Mentions · 2026-08-07: 2Mentions · 2026-08-23: 1Mentions · 2026-09-13: 1Mentions · 2026-09-30: 1PoC Mentioned / Linked · 2026-01-27: 1PoC Mentioned / Linked · 2026-01-31: 1PoC Mentioned / Linked · 2026-02-04: 3PoC Mentioned / Linked · 2026-03-06: 1PoC Mentioned / Linked · 2026-03-12: 1PoC Mentioned / Linked · 2026-03-19: 2PoC Mentioned / Linked · 2026-03-20: 1PoC Mentioned / Linked · 2026-07-12: 1Exploit Tool / Code · 2026-03-12: 1Exploit Tool / Code · 2026-03-19: 1Active Exploitation · 2026-03-01: 1Active Exploitation · 2026-03-03: 1Active Exploitation · 2026-03-04: 3Active Exploitation · 2026-03-05: 1Active Exploitation · 2026-03-06: 1Active Exploitation · 2026-03-08: 1Active Exploitation · 2026-03-11: 3Active Exploitation · 2026-03-12: 18Active Exploitation · 2026-03-13: 11Active Exploitation · 2026-03-14: 2Active Exploitation · 2026-03-15: 1Active Exploitation · 2026-03-16: 3Active Exploitation · 2026-03-17: 1Active Exploitation · 2026-03-19: 3Active Exploitation · 2026-03-20: 2Active Exploitation · 2026-03-23: 2Active Exploitation · 2026-03-25: 2Active Exploitation · 2026-05-26: 1Active Exploitation · 2026-06-13: 1Active Exploitation · 2026-08-04: 1Active Exploitation · 2026-08-05: 1Active Exploitation · 2026-08-07: 1Patch / Workaround · 2026-01-28: 1Patch / Workaround · 2026-02-04: 3Patch / Workaround · 2026-02-05: 3Patch / Workaround · 2026-03-11: 2Patch / Workaround · 2026-03-12: 13Patch / Workaround · 2026-03-13: 6Patch / Workaround · 2026-03-14: 1Patch / Workaround · 2026-03-15: 1Patch / Workaround · 2026-03-16: 4Patch / Workaround · 2026-03-17: 2Patch / Workaround · 2026-03-19: 2Patch / Workaround · 2026-03-20: 1Patch / Workaround · 2026-03-23: 1Patch / Workaround · 2026-03-25: 2Technical Details · 2026-01-31: 1Technical Details · 2026-02-04: 3Technical Details · 2026-02-05: 4Technical Details · 2026-02-06: 2Technical Details · 2026-03-01: 1Technical Details · 2026-03-03: 1Technical Details · 2026-03-04: 1Technical Details · 2026-03-11: 5Technical Details · 2026-03-12: 17Technical Details · 2026-03-13: 10Technical Details · 2026-03-14: 4Technical Details · 2026-03-15: 1Technical Details · 2026-03-16: 5Technical Details · 2026-03-17: 2Technical Details · 2026-03-19: 4Technical Details · 2026-03-20: 2Technical Details · 2026-03-23: 2Technical Details · 2026-03-24: 1Technical Details · 2026-03-25: 3Technical Details · 2026-03-30: 1Technical Details · 2026-04-06: 1Technical Details · 2026-05-26: 1Technical Details · 2026-07-12: 1Technical Details · 2026-08-07: 201-2702-0502-2803-0503-1203-1603-2304-0607-1208-0709-30
Signal classification6 categories
Active Exploitation
5953.2%
Disclosure
1715.3%
General
1513.5%
Patch
1210.8%
Exploit
65.4%
PoC
21.8%
Referenced assets78 URLs
By indicator
Classification over time
DateTotalLabels
2026-01-271
Exploit1
2026-01-282
Disclosure1Patch1
2026-01-311
Exploit1
2026-02-043
Disclosure1Exploit1Patch1
2026-02-055
Disclosure1General1Patch3
2026-02-062
Disclosure1Exploit1
2026-02-111
Disclosure1
2026-02-131
General1
2026-02-281
General1
2026-03-011
Active Exploitation1
2026-03-033
Active Exploitation1Exploit1General1
2026-03-043
Active Exploitation3
2026-03-051
Active Exploitation1
2026-03-061
Active Exploitation1
2026-03-081
Active Exploitation1
2026-03-116
Active Exploitation2Disclosure3Patch1
2026-03-1223
Active Exploitation18General1Patch3PoC1
2026-03-1315
Active Exploitation11Disclosure2General2
2026-03-146
Active Exploitation2Disclosure2General2
2026-03-151
Active Exploitation1
2026-03-165
Active Exploitation2Disclosure2Patch1
2026-03-172
Active Exploitation1Patch1
2026-03-194
Active Exploitation3Exploit1
2026-03-202
Active Exploitation2
2026-03-232
Active Exploitation2
2026-03-241
Disclosure1
2026-03-253
Active Exploitation2Patch1
2026-03-302
Disclosure1General1
2026-04-061
General1
2026-05-261
Active Exploitation1
2026-06-131
Active Exploitation1
2026-06-301
General1
2026-07-121
PoC1
2026-08-021
General1
2026-08-041
Active Exploitation1
2026-08-051
Active Exploitation1
2026-08-072
Active Exploitation1Disclosure1
2026-08-231
General1
2026-09-131
General1
Full discourse20 posts
  • Fatih Çelik@fatihclk01
    Patch

    I recently discovered two new RCE vulnerabilities in n8n. One is a bypass for my previous finding (CVE-2025-68613), and the other is a fresh Command Injection in the Git Node. 1. The Sandbox Escape (CVE-2026-25049) I managed to bypass the fix for my original report (CVE-2025-68613) multiple times. By using Javascript quirks like Template Literals and Object Destructuring, I could escape the sandbox again. The issue has been fixed in n8n versions 1.123.17 and 2.5.2. Users should upgrade to these versions or later to remediate the vulnerability. Full technical analysis: https://fatihhcelik.github.io/posts/n8n-RCEs-A-Tale-of-4-Acts/ 2. Git Node Command Injection (CVE-2026-25053) This one leverages the addConfig operation in the Git Node. It lacks validation, allowing an attacker to inject payloads into core.sshCommand. Leads to RCE. The issue has been fixed in n8n versions 2.5.0, and 1.123.10. Users should upgrade to this version or later to remediate the vulnerability. Full technical analysis: https://fatihhcelik.github.io/posts/n8n-OS-command-inj/ Thanks n8n team!

    Post summary

    The post details two RCE vulnerabilities in n8n, provides technical analysis links, and specifies patch versions for remediation.

    74132108420.9K
    468 followersView on X
  • The Hacker News@TheHackersNews
    Active Exploitation

    ⚠️ CISA confirms active exploitation of CVE-2025-68613 in the #n8n automation platform. The expression-injection flaw allows authenticated attackers to run code with n8n process privileges—exposing data, altering workflows, or taking full control of the instance. 🔗 Read → https://thehackernews.com/2026/03/cisa-flags-actively-exploited-n8n-rce.html

    Post summary

    CISA has confirmed that CVE-2025-68613 in the n8n automation platform is being actively exploited, allowing authenticated attackers to execute code with full process privileges.

    5363982115.1K
    1.1M followersView on X
  • Swissky@pentest_swissky
    Exploit

    n8n CVE-2025-68613 RCE Exploitation: A Detailed Guide @SecureLayer7 https://blog.securelayer7.net/cve-2025-68613-n8n-rce-exploitation/

    Post summary

    A blog guide details how to exploit CVE-2025-68613 in n8n, providing RCE techniques and likely PoC steps, but offers no evidence of active attacks, patches, or debunking.

    09045163.4K
    21.0K followersView on X
  • The Shadowserver Foundation@Shadowserver
    General

    We are continuing to expand our n8n RCE vulnerability scanning - most recently adding CVE-2026-27495 (CVSS 9.4) tagging as well. You can track our various n8n scan results here for the most well known critical vulns: https://dashboard.shadowserver.org/statistics/combined/time-series/?date_range=30&source=http_vulnerable&source=http_vulnerable6&tag=cve-2025-68613%2B&tag=cve-2025-68668%2B&tag=cve-2026-21858%2B&tag=cve-2026-21877%2B&tag=cve-2026-25053%2B&tag=cve-2026-25056%2B&tag=cve-2026-27495%2B&dataset=unique_ips&limit=100&group_by=tag&stacking=overlap&auto_update=on Top affected: US, Germany & France. https://t.co/mEUZ9Is6bf

    Post summary

    The post announces that CVE-2026-27495 has been added to the n8n RCE scanning list and provides a dashboard link, but does not mention PoC, exploit code, patch, or active exploitation.

    112032154.3K
    21.6K followersView on X
  • CISA Cyber@CISACyber
    Disclosure

    🛡️ We added n8n improper control of dynamically-managed code resources vulnerability CVE-2025-68613 to our KEV Catalog. Visit https://go.dhs.gov/Z3Q for more information. #Cybersecurity #InfoSec https://t.co/2OZXSO4ivS

    Post summary

    DHS announced the addition of CVE-2025-68613, an improper control of dynamically-managed code resources vulnerability, to its KEV catalog, indicating a newly disclosed issue that is actively exploited.

    21423157.1K
    292.8K followersView on X
  • blackorbird@blackorbird
    General

    Zerobot + CVE-2025-7544 & CVE-2025-68613 https://www.akamai.com/blog/security-research/2026/feb/zerobot-malware-targets-n8n-automation-platform https://t.co/dkvMy58yum

    Post summary

    The text references two CVE identifiers and a blog link about Zerobot malware targeting n8n, but provides no specific details on exploitation, patches, or technical aspects.

    1602872.7K
    40.2K followersView on X
  • Mr. OS@ksg93rd
    Active Exploitation

    #Malware_analysis 1⃣ Zerobot Malware https://www.akamai.com/blog/security-research/2026/feb/zerobot-malware-targets-n8n-automation-platform // Exploitation of command injection vulnerabilities CVE-2025-7544, CVE-2025-68613 against Tenda AC1206 routers and the n8n automation platform 2⃣ Archive*org Stego Delivers Remcos and AsyncRAT https://www.derp.ca/research/archive-org-stego-campaign // The operator hides .NET injector DLLs inside 4K wallpaper JPEGs using steganography 3⃣ Hydra and Saiga malware https://www.vmray.com/hydra-saiga-covert-espionage-and-infiltration-of-critical-utilities/ 4⃣ Inside a fake Google security check that becomes a browser RAT https://www.malwarebytes.com/blog/privacy/2026/02/inside-a-fake-google-security-check-that-becomes-a-browser-rat 5⃣ Moonrise RAT https://evalian.co.uk/inside-a-new-malware-trojan-moonrise // examines the malware’s WebSocket C&C architecture, JSON-based tasking model, and surveillance capabilities to understand its operational risk

    Post summary

    The text reports that command injection vulnerabilities CVE-2025-7544 and CVE-2025-68613 are actively exploited against Tenda AC1206 routers and the n8n automation platform.

    06021101.9K
    3.1K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    CISA warns of a critical 10.0 CVSS RCE flaw (CVE-2025-68613) in n8n workflow automation. Update to version 1.122.0 immediately to prevent server takeover. https://securityonline.info/cisa-mandates-urgent-patch-for-maximum-10-0-cvss-n8n-rce-flaw/ https://t.co/uqHjB90osr

    Post summary

    CISA warns of a critical RCE flaw (CVE-2025-68613) in n8n workflow automation and recommends an immediate patch to version 1.122.0 to prevent server takeover.

    180911.1K
    10.6K followersView on X
  • SC Media@SCMagazine
    Patch

    .@CISAgov added a critical @n8n_io RCE flaw (CVE-2025-68613) to its KEV list, citing active exploitation risks. Federal agencies must patch within two weeks to prevent potential full system compromise. #cybersecurity #infosec #ITsecurity #CISO https://bit.ly/4s94ANl

    Post summary

    CISA has added CVE-2025-68613, a critical RCE vulnerability in n8n.io, to its KEV list noting active exploitation risks, and urges federal agencies to patch within two weeks to avoid full system compromise.

    170100734
    119.4K followersView on X
  • piyokango@piyokango
    PoC

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(3/11追加) 🛡️No.1541 CVE-2025-68613 n8n Improper Control of Dynamically-Managed Code Resources Vulnerability ============= ✅概要 ・深刻度:緊急🔥9.9 (CVSS Base) / GitHub, Inc. ・種別:動的に操作されるコードリソースの不適切な制御 (CWE-913) ・CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H ---------------------- ✅ChatGPTによる脆弱性評価 ・国内影響度判定:中 ・悪用難易度:中 ---------------------- ✅攻撃前提条件 ・認証済攻撃者がワークフローを作成・編集できること ---------------------- ✅悪用時影響 ・サーバー上で任意コードの実行 ・APIキーや認証情報の窃取 ・ワークフローの改ざん ・サーバーの掌握 ---------------------- ✅悪用事例等に関する情報 ・PoC/Exploit:公開済み ・ITW:大規模な悪用事例の報告確認できず (2026/02/06報告) ---------------------- ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2025-68613 https://github.com/n8n-io/n8n/security/advisories/GHSA-v98v-ff95-f3cp https://www.techradar.com/pro/security/critical-n8n-flaws-discovered-heres-how-to-stay-safe https://www.cisa.gov/news-events/alerts/2026/03/11/cisa-adds-one-known-exploited-vulnerability-catalog https://github.com/wioui/n8n-CVE-2025-68613-exploit https://r1999.com/posts/cve-2025-68613/ #vulnerability

    Post summary

    CISA has added CVE-2025-68613 to its known exploited catalog, noting that a public PoC and exploit code exist but there are no reports of large‑scale in‑the‑wild exploitation yet.

    0201325.2K
    42.7K followersView on X
  • Yash Raikar@Yrctrlsec
    General

    Completed the n8n: CVE-2025-68613 room on TryHackMe The platform built to automate everything… Can also automate your worst day if it’s vulnerable https://t.co/j28dPdvb34

    Post summary

    The user announces having finished the TryHackMe room focused on the n8n CVE-2025-68613 vulnerability, but provides no detailed information, PoC, or exploitation evidence.

    21090340
    38 followersView on X
  • Olivia Murphy || EthicForge Cybersecurity@EthicForgecyber
    Active Exploitation

    CISA adds n8n RCE vulnerability CVE-2025-68613 to Known Exploited Vulnerabilities catalog amid active attacks. Over 24,700 unpatched instances remain online despite December 2025 patches.

    Post summary

    CISA highlights that CVE-2025-68613, an RCE issue in n8n, is actively exploited with 24,700+ unpatched instances, and it has been added to the Known Exploited Vulnerabilities catalog.

    15050204
    2 followersView on X
  • Olivia Murphy || EthicForge Cybersecurity@EthicForgecyber
    Disclosure

    ALERT — A critical RCE flaw (CVSS 9.9) was found in the n8n workflow automation platform. CVE-2025-68613 letsauthenticated users execute arbitrary code, enabling full instance takeover, data access, and system-level actions. More than 103k exposed instances are observed globally

    Post summary

    The post announces CVE-2025-68613, a critical RCE vulnerability in the n8n platform, stating 103k+ exposed instances worldwide.

    05050197
    2 followersView on X
  • VulnCheck@VulnCheckAI
    General

    VulnCheck research shows a gap in CISA KEV. CVE-2025-68613 can be chained with multiple vulnerabilities for unauthenticated access, but not all are represented in CISA KEV. 14K+ exposed instances & links to MuddyWater suggest the risk is understated: https://www.vulncheck.com/blog/n8n-needs-more-kev

    Post summary

    VulnCheck research highlights a gap in the CISA KEV list for CVE‑2025‑68613, noting 14,000+ exposed instances and potential chaining to unauthenticated access, suggesting an understated risk.

    00061520
    761 followersView on X
  • Patrick Roland@DeusLogica
    Disclosure

    ⚠️ CISA KEV: n8n workflow automation RCE (CVE-2025-68613) Workflow automation platforms are the new target. Unauthenticated remote code execution in n8n - the 'fair-code' alternative to Zapier. If you're automating workflows with n8n in your DIS environment, read this thread 👇

    Post summary

    The tweet announces a CISA KEV for an unauthenticated remote code execution vulnerability (CVE-2025-68613) in n8n, but it does not provide PoC, exploit code, patch details, or evidence of active exploitation.

    60010301
    331 followersView on X
  • SC Media@SCMagazine
    Active Exploitation

    .@CISAgov added a critical @n8n_io RCE flaw (CVE-2025-68613) to its KEV list, citing active exploitation risks. Federal agencies must patch within two weeks to prevent potential full system compromise. #cybersecurity #infosec #ITsecurity #CISO https://bit.ly/4s94ANl

    Post summary

    CISA flagged CVE‑2025‑68613 as actively exploited, urging federal agencies to patch within two weeks to mitigate a critical RCE vulnerability.

    01050800
    119.4K followersView on X
  • SC Media@SCMagazine
    Active Exploitation

    .@CISAgov added a critical @n8n_io RCE flaw (CVE-2025-68613) to its KEV list, citing active exploitation risks. Federal agencies must patch within two weeks to prevent potential full system compromise. #cybersecurity #infosec #ITsecurity #CISO https://bit.ly/4s94ANl

    Post summary

    CISA added CVE-2025-68613, a critical RCE flaw in n8n, to its KEV list due to active exploitation, urging federal agencies to patch within two weeks to prevent full system compromise.

    02030702
    119.4K followersView on X
  • cipherX@scooby_dooby123

    Just completed the n8n: CVE-2025-68613 room on TryHackMe 🔐 A great hands-on session covering vulnerability analysis, exploitation, and detection Always fun learning by breaking things and understanding how to secure them. #CyberSecurity #TryHackMe #InfoSec #Learninginpublic https://t.co/lGyGpa95cQ

    0004098
    201 followersView on X
  • kinneko@kinneko
    Active Exploitation

    #HermesAgent こんな使い方もされているのか。しかし、バレ方が間抜け感。 中国語圏の攻撃者、DeepSeekとHermes Agentで自律型 サイバー攻撃を実行 Unit 42が7件の脆弱性 悪用を確認(CVE-2026-33017,CVE-2026-21858/CVE-2025-68613) https://rocket-boys.co.jp/security-measures-lab/chinese-actor-deepseek-hermes-agent-autonomous-attack/

    Post summary

    The tweet reports that Chinese attackers used DeepSeek and Hermes Agent to autonomously exploit seven vulnerabilities, confirmed by Unit 42, indicating active exploitation in the wild.

    00031333
    2.8K followersView on X
  • SC Media@SCMagazine
    Active Exploitation

    .@CISAgov added a critical @n8n_io RCE flaw (CVE-2025-68613) to its KEV list, citing active exploitation risks. Federal agencies must patch within two weeks to prevent potential full system compromise. #cybersecurity #infosec #ITsecurity #CISO https://bit.ly/4s94ANl

    Post summary

    The tweet reports that CISAgov added CVE-2025-68613, an RCE flaw, to its KEV list, warns of active exploitation, and urges federal agencies to patch within two weeks.

    02020606
    119.4K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appn8nn8n-node.js-
Appn8nn8n1.121.0node.js-

Explore more