logo

Critical n8n Automation Platform Vulnerability Enables RCE Attacks – 103,000+ Instances Exposed

ID: beeee9c4-95a0-5371-b20b-b5fa364b0755

STIX ID: report--beeee9c4-95a0-5371-b20b-b5fa364b0755

Feed Name: cybersecurityNews.com

Threat Score
88/100

Date Published: 2025-12-23

Date Updated: 2026-04-21

Author: Abinaya

...
...

A critical authenticated remote code execution vulnerability (CVE-2025-68613, CVSS 9.9) was disclosed in the n8n workflow automation platform, affecting versions from 0.211.0 up to (but not including) 1.120.4, 1.121.1, and 1.122.0; patches are available in releases 1.120.4, 1.121.1, and 1.122.0. The flaw allows arbitrary code execution with full process privileges via unsafe workflow expression evaluation, potentially enabling full system compromise; a proof-of-concept has been published and Censys identifies approximately 103,476 potentially vulnerable instances, so immediate patching and permission hardening are recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.