CVE-2025-68668General(n8n / n8n)

LOWCVSS 9.9 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch n8n n8n systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

n8n is an open source workflow automation platform. From version 1.0.0 to before 2.0.0, a sandbox bypass vulnerability exists in the Python Code Node that uses Pyodide. An authenticated user with permission to create or modify workflows can exploit this vulnerability to execute arbitrary commands on the host system running n8n, using the same privileges as the n8n process. This issue has been patched in version 2.0.0. Workarounds for this issue involve disabling the Code Node by setting the environment variable NODES_EXCLUDE: "[\"n8n-nodes-base.code\"]", disabling Python support in the Code node by setting the environment variable N8N_PYTHON_ENABLED=false, which was introduced in n8n version 1.104.0, and configuring n8n to use the task runner based Python sandbox via the N8N_RUNNERS_ENABLED and N8N_NATIVE_PYTHON_RUNNER environment variables.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-693

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • n8n

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 3d ago at 1 mentions (2026-01-28); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
n8n

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-01-28: 1Mentions · 2026-02-04: 1Mentions · 2026-02-08: 1Mentions · 2026-03-03: 1PoC Mentioned / Linked · 2026-01-28: 1PoC Mentioned / Linked · 2026-02-04: 1Patch / Workaround · 2026-01-28: 1Patch / Workaround · 2026-02-04: 1Technical Details · 2026-02-04: 1Technical Details · 2026-03-03: 101-2802-0402-0803-03
Signal classification3 categories
General
250.0%
Patch
125.0%
Disclosure
125.0%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-01-281
Patch1
2026-02-041
Disclosure1
2026-02-081
General1
2026-03-031
General1
Full discourse4 posts
  • The Shadowserver Foundation@Shadowserver
    General

    We are continuing to expand our n8n RCE vulnerability scanning - most recently adding CVE-2026-27495 (CVSS 9.4) tagging as well. You can track our various n8n scan results here for the most well known critical vulns: https://dashboard.shadowserver.org/statistics/combined/time-series/?date_range=30&source=http_vulnerable&source=http_vulnerable6&tag=cve-2025-68613%2B&tag=cve-2025-68668%2B&tag=cve-2026-21858%2B&tag=cve-2026-21877%2B&tag=cve-2026-25053%2B&tag=cve-2026-25056%2B&tag=cve-2026-27495%2B&dataset=unique_ips&limit=100&group_by=tag&stacking=overlap&auto_update=on Top affected: US, Germany & France. https://t.co/mEUZ9Is6bf

    Post summary

    The post announces that the team has added CVE-2026-27495 to their n8n RCE scanning and provides a link to their dashboard for tracking critical vulnerabilities, but does not mention PoC, exploit code, active exploitation, patches, or false positives.

    112032154.3K
    21.6K followersView on X
  • Komodo Cyber Security@Komodosec
    General

    #VulnerabilityReport #CVE202568668 n8n Sandbox Escape: How CVE-2025-68668 Turns Workflows into Weapons https://securityonline.info/n8n-sandbox-escape-how-cve-2025-68668-turns-workflows-into-weapons/?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    The tweet merely references an article about CVE-2025-68668 without giving further details.

    00010173
    1.5K followersView on X
  • 趣テクノロジー@omomuki_tech
    Disclosure

    オープンソースのワークフロー自動化ツールn8nに、環境を抜け出してホストサーバーを完全に制御できてしまう、複数の重大な脆弱性が公開されました。 その一つは、n8nのPython Code Nodeに存在するサンドボックスバイパスの脆弱性(CVE-2025-68668)です。 これにより、ワークフローの作成や変更権限を持つ認証済みユーザーが、意図されたセキュリティサンドボックスを回避できてしまいます。 攻撃者は特別に細工したPythonコードをワークフローに埋め込むことでPyodideのサンドボックスから脱出し、n8nプロセスと同じ権限でホストシステム上で任意のコマンドを実行できるようになります。 この脆弱性の深刻度はCVSSスコアで9.9と評価されています。 この悪用が成功すると、マルウェアの展開、機密データの窃取、ネットワーク内での横展開、そして最終的にはシステム全体の完全な侵害につながる可能性があります。 この問題はn8nのバージョン1.0.0から1.111.0までが影響を受けます。 また、これとは別に、ワークフローの式評価システムにおける不十分な分離を悪用する脆弱性(CVE-2025-68613、CVSS 9.9)や、認証なしでリモートからコードを実行できる可能性があるWebhookロジックの脆弱性(CVE-2026-21858、CVSS 10.0)も報告されています。 開発元のn8nは対策として、より安全な分離モデルを提供するタスクランナーベースのネイティブPython実行モデルを実装したバージョン2.0.0などをリリースしています。 影響を受けるバージョンの利用者は、直ちにパッチが適用されたバージョンへアップグレードすることが強く推奨されます。 #n8n #脆弱性 #サイバーセキュリティ https://www.bleepingcomputer.com/news/security/critical-n8n-flaws-disclosed-along-with-public-exploits/

    Post summary

    Critical vulnerabilities in n8n, including a sandbox bypass allowing host compromise, have been disclosed; public exploits exist and a patch is available in version 2.0.0.

    0000065
    239 followersView on X
  • Gergely Ignácz@igz4rd
    Patch

    IMPORTANT: Upgrade your self hosted n8n! All supported versions prior to 2.0.0 are affected. CVE-2025-68613 https://github.com/n8n-io/n8n/security/advisories/GHSA-v98v-ff95-f3cp CVE-2025-68668 https://github.com/n8n-io/n8n/security/advisories/GHSA-62r4-hw23-cc8v CVE-2026-21858 https://github.com/n8n-io/n8n/security/advisories/GHSA-v4pr-fm98-w9pg CVE-2026-21877 https://github.com/n8n-io/n8n/security/advisories/GHSA-v364-rw7m-3263

    Post summary

    The message urges users to upgrade their self‑hosted n8n installations to version 2.0.0 or later to remediate several disclosed CVEs.

    0000098
    129 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appn8nn8n-node.js-

Explore more