New n8n Vulnerability Allows Attackers to Execute Arbitrary Commands
ID: 36a96c6c-31b2-5db9-8fe9-e7a8d0e6fb15
STIX ID: report--36a96c6c-31b2-5db9-8fe9-e7a8d0e6fb15
Feed Name: GBHackers
Threat Score
A critical sandbox-bypass vulnerability (CVE-2025-68668, CVSS 9.1) in n8n's Pyodide-based Python Code Node allows authenticated users with workflow creation/modification privileges to execute arbitrary system commands; versions 1.0.0 through 1.999.999 are affected, n8n 2.0.0 contains a full fix, and workarounds (disabling the Code Node or disabling Python support / enabling the native Python runner) are available.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
