Security researchers reported critical vulnerabilities in the open-source workflow automation platform n8n that can enable server takeover and credential compromise, with particular risk to AI-orchestration use cases where workflows handle sensitive API keys and prompts. Pillar Security described a pair of maximum-severity sandbox escape issues (patched in n8n 2.4.0) that could allow attackers to intercept prompts, tamper with AI outputs, divert traffic, and exfiltrate sensitive data; they also warned that a single compromised n8n Cloud account could be leveraged to access shared Kubernetes infrastructure and potentially other customers’ data. Recommended mitigations included immediate patching, rotating encryption keys and credentials, and auditing/monitoring workflows for abuse.
Separately, Cyble reported observed attack attempts against CVE-2025-68613, described as a critical RCE condition in n8n where authenticated users can supply workflow expressions that execute in an insufficiently isolated context, potentially leading to arbitrary code execution with n8n privileges and full system compromise. Cyble stated the issue is fixed in n8n 1.120.4, 1.121.1, and 1.122.0, and noted broader attacker interest in newly disclosed vulnerabilities with public PoCs—raising the likelihood of near-term exploitation for exposed or unpatched n8n deployments.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Researchers reported that n8n was affected by two maximum-severity sandbox escape vulnerabilities that could be chained for full server takeover, credential compromise, prompt interception, and data exfiltration. The issues were patched in n8n version 2.4.0, with users advised to upgrade and rotate keys and credentials.
Cyble reported that its honeypots detected attack attempts exploiting CVE-2025-68613, indicating active interest in the critical n8n flaw. The report also highlighted broader threat-actor discussion and exploitation activity around other high-impact vulnerabilities.
A critical remote code execution vulnerability tracked as CVE-2025-68613 in the n8n workflow automation platform was fixed in versions 1.120.4, 1.121.1, and 1.122.0. The flaw increased the risk of real-world exploitation against exposed n8n deployments.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.