
Proof-of-concept exploit for CVE-2025-68613, a critical RCE vulnerability in n8n workflow automation via expression injection in the executeCommand node.
For educational and authorized security research purposes only.
Critical RCE vulnerability (CVSS 9.9) in n8n workflow automation platform. Authenticated users can execute arbitrary OS commands via the executeCommand node, bypassing sandbox restrictions.
| Field | Detail |
|---|---|
| CVE | CVE-2025-68613 |
| CVSS | 9.9 (Critical) |
| Affected versions | >= 0.211.0 < 1.120.4 |
| Auth required | Yes (any user with workflow creation permissions) |
| Tested on | n8n 1.119.1 |
| Fixed in | 1.120.4, 1.121.1, 1.122.0 |
n8n evaluates workflow node parameters on the server side. The executeCommand node runs shell commands directly on the host with the privileges of the n8n process. Any authenticated user with workflow creation or edit permissions can abuse this to achieve full RCE.
bash poc_final.sh <target> <email> <password> <command>
Examples:
# Basic RCE
bash poc_final.sh http://target:5678 [email protected] 'Password1!' 'id'
# Read environment variables (may contain credentials/API keys)
bash poc_final.sh http://target:5678 [email protected] 'Password1!' 'env'
# Read sensitive files
bash poc_final.sh http://target:5678 [email protected] 'Password1!' 'cat /etc/passwd'
# List n8n data directory
bash poc_final.sh http://target:5678 [email protected] 'Password1!' 'ls -la ~/.n8n/'
Note: If your password contains special characters like
!, use single quotes.
Upgrade to n8n >= 1.120.4 immediately.
If upgrading is not immediately possible:
This tool is provided for educational purposes and authorized security testing only. Unauthorized use against systems you do not own or have explicit written permission to test is illegal. The author is not responsible for any misuse.