CISA orders feds to patch n8n RCE flaw exploited in attacks
ID: c32d8448-d6f3-5c48-95d6-b1841f7fe5db
STIX ID: report--c32d8448-d6f3-5c48-95d6-b1841f7fe5db
Feed Name: Bleeping Computer
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that n8n — a widely used open-source workflow automation platform — contains a remote code execution flaw tracked as CVE-2025-68613 that allows authenticated attackers to run arbitrary code with the n8n process privileges, potentially exposing API keys, database credentials, OAuth tokens and other sensitive secrets; n8n released v1.122.0 to patch the issue, Shadowserver reports over 40,000 exposed unpatched instances, and CISA added the flaw to its Known Exploited Vulnerabilities catalog and ordered federal agencies to remediate by March 25 (BOD 22-01), while recommending mitigations for those unable to immediately upgrade.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
