CVE-2025-68668: Arbitrary Command Execution in n8n Python Code Node
ID: c6cba0bd-6396-5e06-a7ec-bc58e6f8c033
STIX ID: report--c6cba0bd-6396-5e06-a7ec-bc58e6f8c033
Feed Name: SOCRadar Blog
Threat Score
**CVE-2025-68668:** A critical (CVSS 9.9) sandbox bypass in n8n's Python Code Node (Pyodide-based) allows authenticated users who can create or modify workflows to escape the sandbox and run arbitrary OS commands; it affects n8n versions 1.0.0 through <2.0.0 and is mitigated by upgrading to 2.0.0 or disabling the Code Node / Python support or enabling the native task-runner Python execution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
