A critical vulnerability (CVE-2025-68668) has been disclosed in the open-source workflow automation platform n8n, allowing authenticated users with workflow creation or modification permissions to execute arbitrary system commands on the host system. The flaw, rated 9.9 on the CVSS scale, is due to a protection mechanism failure in the Python Code Node, which leverages Pyodide for code execution. This vulnerability affects all n8n versions from 1.0.0 up to, but not including, 2.0.0, and has been fully addressed in version 2.0.0. The issue enables attackers to run commands with the same privileges as the n8n process, potentially leading to data access, lateral movement, or further compromise depending on deployment.
n8n has provided several mitigation steps, including disabling the Code Node or Python support via environment variables, and recommends enabling the task runner-based Python sandbox for improved isolation. The vulnerability was reported by security researcher csuermann and published under advisory GHSA-62r4-hw23-cc8v. Users are strongly advised to upgrade to version 2.0.0 or apply the recommended workarounds to mitigate the risk of exploitation. The disclosure highlights the importance of securing workflow automation platforms, especially those handling sensitive integrations and credentials.

See real exploitation activity before you spend the cycle.
4 events from the most recent confirmed update back to the earliest known activity.
Multiple sources disclosed CVE-2025-68668 as a critical 9.9 CVSS vulnerability in n8n's Python Code Node that can let authenticated users execute arbitrary system commands on the host. Public guidance recommended upgrading to 2.0.0 or applying mitigations such as disabling the Code Node, disabling Python support, or enabling the task runner-based sandbox.
n8n resolved CVE-2025-68668 in version 2.0.0 by making a task runner-based native Python implementation the default, replacing the riskier Pyodide-based approach. The fix addresses affected versions from 1.0.0 up to but not including 2.0.0.
Security researcher csuermann reported a critical sandbox-bypass flaw in n8n's Python Code Node, later tracked as CVE-2025-68668 and published under advisory GHSA-62r4-hw23-cc8v. The issue allows authenticated users with workflow creation or modification permissions to execute arbitrary system commands.
n8n previously introduced a task runner-based native Python implementation as an optional feature in version 1.111.0. This later became relevant as a mitigation path for the Python Code Node vulnerability.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
5 references tracked. Mallory keeps watching after this page renders.
vulncheck.com
Open sourcethehackernews.com
Open sourcethecyberexpress.com
Open sourcesocradar.io
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.