Critical n8n Flaw (CVSS 9.9) Enables Arbitrary Code Execution Across Thousands of Instances

The n8n workflow automation platform has been found to have a severe security flaw that, if successfully exploited, might lead to arbitrary code execution in specific situations.

The vulnerability has a CVSS score of 9.9 out of a possible 10.0, and it is tagged as CVE-2025-68613. According to npm data, the package receives roughly 57,000 downloads every week.

According to the npm package maintainers, expressions provided by authenticated users during workflow configuration may, in some circumstances, be evaluated in an execution environment that is not adequately separated from the underlying runtime.

This behavior could be abused by an authenticated attacker using the n8n process’s privileges to run arbitrary code. If the exploitation is successful, the impacted instance may be completely compromised, allowing for the execution of system-level actions read more about Critical n8n Flaw (CVSS 9.9) Enables Arbitrary Code Execution Across Thousands of Instances.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *