vulnerability
n8n:CVE-2025-68613: Insufficient sandbox isolation in workflow expression evaluation
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 10 | (AV:N/AC:L/Au:S/C:C/I:C/A:C) | Dec 19, 2025 | Jan 9, 2026 | Mar 12, 2026 |
Severity
10
CVSS
(AV:N/AC:L/Au:S/C:C/I:C/A:C)
Published
Dec 19, 2025
Added
Jan 9, 2026
Modified
Mar 12, 2026
Description
A critical RCE vulnerability exists in n8n's workflow expression evaluation engine. Authenticated users can inject crafted expressions that escape the intended execution context due to inadequate sandbox isolation. This allows for arbitrary code execution on the underlying host. Affected versions: >= 0.211.0 and prior to 1.120.4, 1.121.1, and 1.122.0.
Solution
n8n-upgrade-1_122_0
Rapid7 Labs
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.