Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Critical n8n Vulnerability Exposes 103,000+ Automation Instances to RCE Attacks

## Cybersecurity: n8n Critical Vulnerability

Cybersecurity: n8n Critical Vulnerability

A critical remote code execution vulnerability has been identified in n8n, a widely-used open-source workflow automation platform, affecting over 103,000 instances globally. This vulnerability is tracked as CVE-2025-68613 and has been assigned a CVSS severity score of 9.9, indicating a critical threat level. It allows authenticated attackers to execute arbitrary code with n8n process privileges, posing a risk of complete instance compromise.

Vulnerability Details and Attack Vector

The vulnerability affects n8n versions from 0.211.0 up to 1.120.3, 1.121.0, and earlier 1.122.x releases. It arises from insufficient isolation within n8n's workflow expression evaluation system. Authenticated users can exploit this flaw by providing specially crafted expressions during workflow configuration, leading to arbitrary code execution on the underlying runtime.

Successful exploitation can result in unauthorized access to sensitive data, workflow modification capabilities, and system-level operation execution, effectively compromising the entire automation infrastructure.

This vulnerability is tracked as CVE-2025-68613 and has been assigned a CVSS severity score of 9.9, indicating a critical threat level.
Adam Foster · Thehackingpost

n8n has released patched versions: 1.120.4, 1.121.1, and 1.122.0 and later, to address this critical vulnerability. Organizations are advised to upgrade immediately to one of these patched releases. For those unable to patch immediately, n8n recommends temporary mitigations such as restricting workflow creation and editing permissions to trusted users and deploying n8n in secured environments with minimal operating system privileges and restricted network access. However, these measures offer only partial protection and should be considered as emergency controls until proper patching is executed.

Censys has identified 103,476 potentially vulnerable n8n instances across the internet, highlighting the platform's significant adoption within enterprise automation ecosystems. The vulnerability poses a substantial supply chain risk, as compromised n8n instances could serve as entry points into upstream and downstream systems, affecting entire connected digital ecosystems.

Advertisement

Security teams should promptly identify n8n deployments within their environments, verify current version numbers, and prioritize upgrading to patched versions. Organizations using n8n for critical business processes should treat this vulnerability as an urgent security incident requiring immediate executive attention and resource allocation.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories