Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacyยฉ 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-68613-n8n-rce-analysis โ€” CVE-2025-68613 (n8n) Critical RCE analysis + defensive recommendations (patch validation, detection ideas, and hardening tips) | Kitploit
Tools/GitHubGitHub/ak-cybe/cve-2025-68613-n8n-rce-analysis
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingLearning & EducationIncident Response
GitHubak-cybe/cve-2025-68613-n8n-rce-analysis

CVE-2025-68613-n8n-rce-analysis

CVE-2025-68613 (n8n) Critical RCE analysis + defensive recommendations (patch validation, detection ideas, and hardening tips)

View Repository
1129 months agoNot yet reviewed

Most Popular

View all โ†’

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools โ†’
Share

Header Banner

Typing SVG

Severity CVSS Instances Status CWE

Hacker GIF Matrix GIF


Divider

๐Ÿ“‘ Table of Contents

  • ๐ŸŽฏ Executive Summary
  • ๐Ÿ› The Vulnerability
  • ๐Ÿ”ฌ Technical Analysis
  • ๐Ÿ’€ Exploitation Walkthrough
  • ๐Ÿ’ฅ Impact Assessment
  • ๐Ÿ” Detection & Response
  • ๐Ÿ›ก๏ธ Mitigation Strategy
  • ๐Ÿ“š References

๐ŸŽฏ Executive Summary

Alert GIF

CVE-2025-68613 is a critical remote code execution vulnerability in n8n's workflow automation platform that allows authenticated attackers to execute arbitrary system commands through expression injection.

โšก Quick Stats

๐Ÿ”ฅ Metric๐Ÿ“Š Value
CVSS Score9.9 / 10
Exposed Instances103,476+
Attack ComplexityLOW
Auth RequiredYes (Low Priv)
User InteractionNone

๐ŸŽฏ Key Facts

๐Ÿ“Œ Property๐Ÿ“ Value
DisclosedDec 18, 2025
VectorNetwork (AV:N)
ScopeChanged
ImpactCIA = HIGH
Exploit TypeExpression Injection

๐Ÿ› The Vulnerability

Bug GIF

๐Ÿ“‹ CVE Overview

PropertyValue
๐Ÿ†” CVE IDCVE-2025-68613
๐Ÿ“Š CVSS Score9.9 (Critical) ๐Ÿ”ด
๐Ÿ”— CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
๐Ÿท๏ธ CWECWE-913 (Improper Control of Dynamically-Managed Code Resources)
๐Ÿ“ฆ Affected Versions0.211.0 โ†’ 1.120.3, 1.121.0
โœ… Patched Versions1.120.4, 1.121.1, 1.122.0+

๐Ÿค– What is n8n?

n8n is an open-source workflow automation platform enabling no-code/low-code integration across 400+ applications. It's widely deployed in:

๐Ÿข Use Case๐Ÿ“ Description
๐Ÿ”ง DevOpsAutomation pipelines, CI/CD integrations
๐Ÿ›ก๏ธ Security OpsSOAR workflows, incident response
๐Ÿ’ผ BusinessProcess automation, data workflows
๐Ÿ“Š DataETL processes, API integrations

๐Ÿ”ง Technical Root Cause

๐Ÿ”“ VULNERABILITY CHAIN:
โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚  ๐Ÿ“ n8n Expression Language โ†’ Dynamic Data Handling            โ”‚
โ”‚                           โ†“                                     โ”‚
โ”‚  โš ๏ธ  Insufficient Sandbox Isolation in Server-Side Eval        โ”‚
โ”‚                           โ†“                                     โ”‚
โ”‚  ๐Ÿ’€ Malicious Expression Escapes Sandbox                       โ”‚
โ”‚                           โ†“                                     โ”‚
โ”‚  ๐Ÿ–ฅ๏ธ  Access to Node.js child_process Module                    โ”‚
โ”‚                           โ†“                                     โ”‚
โ”‚  ๐Ÿ’ฅ FULL RCE - OS Command Execution                            โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

๐Ÿ”ฌ Technical Analysis

Analysis GIF

๐ŸŽฏ Attack Surface

Prerequisites for Exploitation:

#๐Ÿ“‹ Requirement๐Ÿ“ Details
1๏ธโƒฃAuthenticationValid n8n user account (low-privilege sufficient)
2๏ธโƒฃPermissionsWorkflow creation/editing capability
3๏ธโƒฃNetwork AccessAbility to reach n8n instance

โš”๏ธ Attack Characteristics

๐Ÿท๏ธ Attribute๐Ÿ“Š Value๐Ÿ”ฅ Risk
ComplexityLOW (AC:L)๐Ÿ”ด High
User InteractionNone Required๐Ÿ”ด High
ScopeChanged๐Ÿ”ด Critical

๐Ÿ—บ๏ธ Vulnerability Flow Diagram

graph TD
    A[๐Ÿ” Authenticated User] -->|Creates| B[๐Ÿ“ New Workflow]
    B -->|Injects| C[๐Ÿ’€ Malicious Expression]
    C -->|Triggers| D[โšก Expression Evaluation]
    D -->|Exploits| E[๐Ÿ”“ Sandbox Escape]
    E -->|Accesses| F[๐Ÿ–ฅ๏ธ Node.js Runtime]
    F -->|Executes| G[๐Ÿ’ฅ OS Command via child_process]
    G -->|Achieves| H[โ˜ ๏ธ FULL SERVER COMPROMISE]
    
    style A fill:#4CAF50,color:#fff
    style C fill:#ff9800,color:#fff
    style E fill:#f44336,color:#fff
    style H fill:#9c27b0,color:#fff

๐Ÿ’€ Exploitation Walkthrough

Hacking GIF

โš ๏ธ DISCLAIMER: The following is for educational purposes only. Unauthorized exploitation is illegal.

๐Ÿ“ธ Step-by-Step Exploitation Screenshots

๐Ÿ–ฅ๏ธ Step 1: Access n8n Instance

Initial access to vulnerable n8n workflow automation platform.

n8n Welcome Screen
๐Ÿ”“ n8n Welcome Dashboard - Entry Point


โž• Step 2: Create New Workflow

Create a new workflow that will contain the malicious payload.

New Workflow Creation
๐Ÿ“ Creating new workflow with "Add first step"


โšก Step 3: Add Manual Trigger

Configure workflow trigger - Manual Trigger allows on-demand execution.

Download Tool