vulnerability

n8n:CVE-2025-68613: Insufficient sandbox isolation in workflow expression evaluation

Severity
10
CVSS
(AV:N/AC:L/Au:S/C:C/I:C/A:C)
Published
Dec 19, 2025
Added
Jan 9, 2026
Modified
Mar 12, 2026

Description

A critical RCE vulnerability exists in n8n's workflow expression evaluation engine. Authenticated users can inject crafted expressions that escape the intended execution context due to inadequate sandbox isolation. This allows for arbitrary code execution on the underlying host. Affected versions: >= 0.211.0 and prior to 1.120.4, 1.121.1, and 1.122.0.

Solution

n8n-upgrade-1_122_0
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.