CVE-2025-68613

unknown KEV
Published 2025-12-22 · Modified 2026-03-11
CVSS v3
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS v2
VIR risk
1.5

Description

n8n contains an improper control of dynamically managed code resources vulnerability in its workflow expression evaluation system that allows for remote code execution.

CISA KEV

Vendor
n8n
Product
n8n
Due date
2026-03-25

Predictions

Exploit likelihood
99%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cisa-kev — https://github.com/n8n-io/n8n/security/advisories/GHSA-v98v-ff95-f3cp ; https://nvd.nist.gov/vuln/detail/CVE-2025-68613

Exploits

Package impact

EcosystemPackageVulnerableFixed
npm npmn8n>=0.211.0,<1.120.41.120.4
npm npmn8n>=1.121.0,<1.121.11.121.1

References

Verify integrity in audit chain (admin only). AS-IS.