Back to Labs
Security Advisory

CVE-2025-68613

About

n8n is an open source workflow automation platform. Versions starting with 0.211.0 and prior to 1.120.4, 1.121.1, and 1.122.0 contain a critical Remote Code Execution (RCE) vulnerability in their workflow expression evaluation system. Under certain conditions, expressions supplied by authenticated users during workflow configuration may be evaluated in an execution context that is not sufficiently isolated from the underlying runtime. An authenticated attacker could abuse this behavior to execute arbitrary code with the privileges of the n8n process. Successful exploitation may lead to full compromise of the affected instance, including unauthorized access to sensitive data, modification of workflows, and execution of system-level operations. This issue has been fixed in versions 1.120.4, 1.121.1, and 1.122.0. Users are strongly advised to upgrade to a patched version, which introduces additional safeguards to restrict expression evaluation. If upgrading is not immediately possible, administrators should consider the following temporary mitigations: Limit workflow creation and editing permissions to fully trusted users only; and/or deploy n8n in a hardened environment with restricted operating system privileges and network access to reduce the impact of potential exploitation. These workarounds do not fully eliminate the risk and should only be used as short-term measures.

Weakness (CWE):CWE-913

Rainforest analyst review

The vulnerability is in n8n's workflow expression evaluation. Expressions that authenticated users supply while configuring workflows can, under certain conditions, be evaluated in a context that is not properly isolated from the underlying runtime. An attacker with a valid account abuses that weak isolation to break out of the expression sandbox and execute arbitrary code with the privileges of the n8n process, which can lead to full compromise of the instance, including its stored data and workflows.

n8n is a workflow-automation platform, and its whole purpose is to connect to other systems, so instances typically hold credentials, API keys, and tokens for the services they orchestrate; code execution on the host therefore exposes that entire credential store and the systems it reaches. Because exploitation requires authentication, the exposure is worst where account creation is loose or many users share an instance. Upgrade to 1.120.4, 1.121.1, or 1.122.0 or later. Until then, restrict workflow creation and editing to fully trusted users and run n8n with reduced OS privileges and constrained network access, treating those as stopgaps rather than a fix, and rotate connected-service credentials if compromise is suspected.

References

Related CVEs

Frequently asked questions

What is CVE-2025-68613?

n8n is an open source workflow automation platform. Versions starting with 0.211.0 and prior to 1.120.4, 1.121.1, and 1.122.0 contain a critical Remote Code Execution (RCE) vulnerability in their workflow expression evaluation system.

How severe is CVE-2025-68613?

CVE-2025-68613 carries a CVSS 3.1 base score of 9.9, rated critical. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 100 out of 100, in the critical band.

How is CVE-2025-68613 exploited?

According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H): attack vector Network, attack complexity Low, privileges required Low, user interaction None. Impact on confidentiality High, integrity High and availability High.

Which products are affected by CVE-2025-68613?

Public advisories list the following as affected: n8n. Check the references on this page for the exact versions each vendor confirms.

How do I fix CVE-2025-68613?

Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.

Empower Your Security Strategy with Rainforest

Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.

Share this:LinkedInX Email