CISA Flags Actively Exploited n8n RCE Bug as 24,700 Instances Remain Exposed
Based on evidence of active exploitation, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a significant security vulnerability affecting n8n to its Known Exploited Vulnerabilities (KEV) database on Wednesday.
A case of expression injection that results in remote code execution is the subject of the vulnerability, which is tracked as CVE-2025-68613 (CVSS score: 9.9). In December 2025, n8n fixed the security flaw in versions 1.120.4, 1.121.1, and 1.122.0. The first n8n vulnerability added to the KEV database is CVE-2025-68613.
According to CISA, N8n has a vulnerability in its workflow expression evaluation system that permits remote code execution due to inappropriate control of dynamically managed code resources.
The workflow automation platform's maintainer...

