
CVE-2025-68613 (n8n) Critical RCE analysis + defensive recommendations (patch validation, detection ideas, and hardening tips)
Matrix GIF
CVE-2025-68613 is a critical remote code execution vulnerability in n8n's workflow automation platform that allows authenticated attackers to execute arbitrary system commands through expression injection.
โก Quick Stats
|
๐ฏ Key Facts
|
| Property | Value |
|---|---|
| ๐ CVE ID | CVE-2025-68613 |
| ๐ CVSS Score | 9.9 (Critical) ๐ด |
| ๐ CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
| ๐ท๏ธ CWE | CWE-913 (Improper Control of Dynamically-Managed Code Resources) |
| ๐ฆ Affected Versions | 0.211.0 โ 1.120.3, 1.121.0 |
| โ Patched Versions | 1.120.4, 1.121.1, 1.122.0+ |
n8n is an open-source workflow automation platform enabling no-code/low-code integration across 400+ applications. It's widely deployed in:
| ๐ข Use Case | ๐ Description |
|---|---|
| ๐ง DevOps | Automation pipelines, CI/CD integrations |
| ๐ก๏ธ Security Ops | SOAR workflows, incident response |
| ๐ผ Business | Process automation, data workflows |
| ๐ Data | ETL processes, API integrations |
๐ VULNERABILITY CHAIN:
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ ๐ n8n Expression Language โ Dynamic Data Handling โ
โ โ โ
โ โ ๏ธ Insufficient Sandbox Isolation in Server-Side Eval โ
โ โ โ
โ ๐ Malicious Expression Escapes Sandbox โ
โ โ โ
โ ๐ฅ๏ธ Access to Node.js child_process Module โ
โ โ โ
โ ๐ฅ FULL RCE - OS Command Execution โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
Prerequisites for Exploitation:
| # | ๐ Requirement | ๐ Details |
|---|---|---|
| 1๏ธโฃ | Authentication | Valid n8n user account (low-privilege sufficient) |
| 2๏ธโฃ | Permissions | Workflow creation/editing capability |
| 3๏ธโฃ | Network Access | Ability to reach n8n instance |
| ๐ท๏ธ Attribute | ๐ Value | ๐ฅ Risk |
|---|---|---|
| Complexity | LOW (AC:L) | ๐ด High |
| User Interaction | None Required | ๐ด High |
| Scope | Changed | ๐ด Critical |
graph TD
A[๐ Authenticated User] -->|Creates| B[๐ New Workflow]
B -->|Injects| C[๐ Malicious Expression]
C -->|Triggers| D[โก Expression Evaluation]
D -->|Exploits| E[๐ Sandbox Escape]
E -->|Accesses| F[๐ฅ๏ธ Node.js Runtime]
F -->|Executes| G[๐ฅ OS Command via child_process]
G -->|Achieves| H[โ ๏ธ FULL SERVER COMPROMISE]
style A fill:#4CAF50,color:#fff
style C fill:#ff9800,color:#fff
style E fill:#f44336,color:#fff
style H fill:#9c27b0,color:#fff
โ ๏ธ DISCLAIMER: The following is for educational purposes only. Unauthorized exploitation is illegal.
Initial access to vulnerable n8n workflow automation platform.
๐ n8n Welcome Dashboard - Entry Point
Create a new workflow that will contain the malicious payload.
๐ Creating new workflow with "Add first step"
Configure workflow trigger - Manual Trigger allows on-demand execution.