Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Critical n8n Automation Platform Vulnerability Enables RCE Attacks – 103,000+ Instances Exposed

A critical remote code execution vulnerability, identified as CVE-2025-68613, has been discovered in the n8n open-source workflow automation platform. This vulnerability exposes over 103,000 potentially vulnerable instances globally.

A critical remote code execution vulnerability, identified as CVE-2025-68613, has been discovered in the n8n open-source workflow automation platform. This vulnerability exposes over 103,000 potentially vulnerable instances globally.

The vulnerability, scoring a maximum CVSS severity score of 9.9, affects the workflow expression evaluation system within n8n. It allows authenticated attackers to execute arbitrary code with full process privileges, potentially compromising the entire system.

Under certain conditions, expressions entered by authenticated users are executed without proper isolation, granting access to the underlying system. This flaw allows attackers to bypass security boundaries and execute arbitrary code, leading to unauthorized access to sensitive data stored within workflows. The vulnerability impacts versions from 0.211.0 up to, but not including, 1.120.4, 1.121.1, and 1.122.0.

Patches have been released across three update tracks:

A critical remote code execution vulnerability, identified as CVE-2025-68613, has been discovered in the n8n open-source workflow automation platform.
Lucas Gallagher · Thehackingpost

Track 1: Version 1.120.4 Track 2: Version 1.121.1 Track 3: Version 1.122.0

The n8n security team advises upgrading to the latest patched versions. For organizations unable to update immediately, temporary mitigations include restricting workflow creation to trusted users and deploying n8n in hardened environments with restricted system privileges and network access. However, these measures do not eliminate risk and should be considered short-term solutions.

As of December 19, 2025, no active exploitation has been reported. However, a proof-of-concept exploitation guide has been published, increasing the risk of future attacks. Censys data reveals the exposure of 103,476 potentially vulnerable n8n instances globally, underscoring the urgency of applying patches.

Advertisement

Organizations using n8n should prioritize immediate patching to the latest versions. Security teams are advised to audit workflow permissions, review recent workflow modifications, and monitor system logs for unauthorized activity. Given the critical nature and widespread exposure, this should be treated as a high-priority security incident to protect automation infrastructure and sensitive data.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories