logo

n8n Sandbox Escape: How CVE-2025-68668 Turns Workflows into Weapons

ID: 1f0b5de2-96f5-551b-8c70-5c2912701b79

STIX ID: report--1f0b5de2-96f5-551b-8c70-5c2912701b79

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-01-06

Date Updated: 2026-04-22

Author: Ddos

...
...

A critical vulnerability (CVE-2025-68668) in n8n's Python Code Node (Pyodide) allows authenticated users to escape the intended sandbox via documented Python–JavaScript interoperability and invoke Node.js/system commands, enabling full host takeover; the flaw affects n8n versions 1.0.0 up to but not including 2.0.0, was patched in 2.0.0 (which removes in-process Pyodide), and can be mitigated immediately by disabling Python execution (N8N_PYTHON_ENABLED=false).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.