A critical vulnerability, tracked as CVE-2025-68613, was discovered in the n8n workflow automation platform, allowing authenticated users to execute arbitrary code on affected instances. The flaw, which impacts versions 0.211.0 up to but not including 1.120.4, arises from insufficient isolation of user-supplied expressions during workflow configuration, potentially leading to full system compromise, unauthorized data access, and modification of workflows. The vulnerability has a CVSS score of 9.9, and over 100,000 potentially exposed instances have been identified globally, with the highest concentrations in the U.S., Germany, France, Brazil, and Singapore.
Security advisories urge immediate patching to versions 1.120.4, 1.121.1, or 1.122.0 to mitigate the risk. For organizations unable to patch immediately, it is recommended to restrict workflow creation and editing permissions to trusted users and to deploy n8n in a hardened environment with limited operating system privileges and network access. The Canadian Centre for Cyber Security and other authorities have issued alerts emphasizing the criticality of this vulnerability and the urgent need for remediation.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
On December 25, 2025, a Metasploit Framework pull request introduced an exploit module for CVE-2025-68613. The module targeted authenticated code execution in vulnerable n8n instances through the Schedule Trigger workflow and demonstrated shell access on tested versions.
By December 23-24, 2025, public proof-of-concept code and technical exploitation details for CVE-2025-68613 were published, increasing the likelihood of attacks. Reports described abuse through workflow expression evaluation, including exploitation via the web UI and REST API.
By December 22-23, 2025, public advisories disclosed CVE-2025-68613 as a CVSS 9.9 vulnerability in n8n that could let authenticated users execute arbitrary code and fully compromise servers. Reporting said more than 100,000 internet-exposed instances were potentially vulnerable and urged immediate patching or temporary hardening measures.
On December 19, 2025, n8n released security updates to fix CVE-2025-68613, a critical expression-injection flaw enabling authenticated remote code execution. The issue was patched in versions 1.120.4, 1.121.1, and 1.122.0 for affected releases from 0.211.0 onward.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
9 references tracked. Mallory keeps watching after this page renders.
resecurity.com
Open sourcegithub.com
Open sourceindusface.com
Open sourcescworld.com
Open sourcesocradar.io
Open sourcecybersecuritynews.com
Open sourcethehackernews.com
Open sourcesecurityaffairs.com
Open sourcecyber.gc.ca
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.