Based on evidence of active exploitation, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a significant security vulnerability affecting n8n to its Known Exploited Vulnerabilities (KEV) database on Wednesday.
A case of expression injection that results in remote code execution is the subject of the vulnerability, which is tracked as CVE-2025-68613 (CVSS score: 9.9). In December 2025, n8n fixed the security flaw in versions 1.120.4, 1.121.1, and 1.122.0. The first n8n vulnerability added to the KEV database is CVE-2025-68613.
According to CISA, N8n has a vulnerability in its workflow expression evaluation system that permits remote code execution due to inappropriate control of dynamically managed code resources.
The workflow automation platform’s maintainers claim that an authenticated attacker might use the vulnerability read more about CISA Flags Actively Exploited n8n RCE Bug as 24700 Instances Remain Exposed.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
