Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-68613 — Proof-of-concept exploit for CVE-2025-68613, a critical RCE vulnerability in n8n workflow automation via expression injection in the executeCommand node. | Kitploit
Tools/GitHubGitHub/h3raklez/cve-2025-68613
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingCommand and ControlLearning & Education
GitHubh3raklez/cve-2025-68613

CVE-2025-68613

Proof-of-concept exploit for CVE-2025-68613, a critical RCE vulnerability in n8n workflow automation via expression injection in the executeCommand node.

View Repository
367 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-68613 — n8n RCE via Expression Injection

For educational and authorized security research purposes only.

Overview

Critical RCE vulnerability (CVSS 9.9) in n8n workflow automation platform. Authenticated users can execute arbitrary OS commands via the executeCommand node, bypassing sandbox restrictions.

FieldDetail
CVECVE-2025-68613
CVSS9.9 (Critical)
Affected versions>= 0.211.0 < 1.120.4
Auth requiredYes (any user with workflow creation permissions)
Tested onn8n 1.119.1
Fixed in1.120.4, 1.121.1, 1.122.0

How it works

n8n evaluates workflow node parameters on the server side. The executeCommand node runs shell commands directly on the host with the privileges of the n8n process. Any authenticated user with workflow creation or edit permissions can abuse this to achieve full RCE.

Usage

bash poc_final.sh <target> <email> <password> <command>

Examples:

# Basic RCE
bash poc_final.sh http://target:5678 [email protected] 'Password1!' 'id'

# Read environment variables (may contain credentials/API keys)
bash poc_final.sh http://target:5678 [email protected] 'Password1!' 'env'

# Read sensitive files
bash poc_final.sh http://target:5678 [email protected] 'Password1!' 'cat /etc/passwd'

# List n8n data directory
bash poc_final.sh http://target:5678 [email protected] 'Password1!' 'ls -la ~/.n8n/'

Note: If your password contains special characters like !, use single quotes.

Remediation

Upgrade to n8n >= 1.120.4 immediately.

If upgrading is not immediately possible:

  • Restrict workflow creation and editing to fully trusted users only
  • Run n8n with minimal OS privileges
  • Use network segmentation to limit exposure

References

  • n8n Security Advisory GHSA-v98v-ff95-f3cp
  • NVD — CVE-2025-68613

Disclaimer

This tool is provided for educational purposes and authorized security testing only. Unauthorized use against systems you do not own or have explicit written permission to test is illegal. The author is not responsible for any misuse.

Download Tool