logo

Critical n8n Vulnerability Allows Arbitrary Command Execution (CVE-2025-68668)

ID: 1bead13f-5267-5a35-9b4b-fe659681780c

STIX ID: report--1bead13f-5267-5a35-9b4b-fe659681780c

Feed Name: The Cyber Express

Threat Score
75/100

Date Published: 2026-01-06

Date Updated: 2026-04-23

Author: Ashish Khaitan

...
...

**Executive summary:** A critical sandbox-bypass vulnerability (CVE-2025-68668, CVSS 9.9) in n8n's Python Code Node using Pyodide allows authenticated users who can create or modify workflows to execute arbitrary system commands on the host; the flaw affects versions from 1.0.0 up to but not including 2.0.0, is fixed in n8n 2.0.0, and administrators can mitigate exposure by disabling the Code Node or Python support or enabling the task-runner/native Python sandbox.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.