logo

CVE-2025-68668: Arbitrary Command Execution in n8n Python Code Node

ID: c6cba0bd-6396-5e06-a7ec-bc58e6f8c033

STIX ID: report--c6cba0bd-6396-5e06-a7ec-bc58e6f8c033

Feed Name: SOCRadar Blog

Threat Score
78/100

Date Published: 2026-01-06

Date Updated: 2026-04-30

Author: Ameer Owda

...
...

**CVE-2025-68668:** A critical (CVSS 9.9) sandbox bypass in n8n's Python Code Node (Pyodide-based) allows authenticated users who can create or modify workflows to escape the sandbox and run arbitrary OS commands; it affects n8n versions 1.0.0 through <2.0.0 and is mitigated by upgrading to 2.0.0 or disabling the Code Node / Python support or enabling the native task-runner Python execution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.