LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-68613: n8n Improper Control of Dynamically-Managed Code Resources Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 11, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 25, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-68613 to its Known Exploited Vulnerabilities catalog on Mar 11, 2026, with a federal patch deadline of Mar 25, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

n8n contains an improper control of dynamically managed code resources vulnerability in its workflow expression evaluation system that allows for remote code execution.

n8n contains an improper control of dynamically managed code resources vulnerability in its workflow expression evaluation system that allows for remote code execution.

Organizations running n8n for automation should treat this as a priority because successful exploitation can grant attackers the ability to run arbitrary code on the affected system.

How it works

The flaw is categorized under CWE-913. It stems from insufficient restrictions on dynamically managed code resources within the workflow expression evaluation system, enabling an attacker to supply input that results in remote code execution.

Am I affected? How to find it in your systems

n8n is a workflow automation platform commonly deployed in cloud or self-hosted environments. Begin by locating all n8n instances through asset inventories, container registries, or orchestration platforms.

How to remediate

Apply mitigations per vendor instructions. Follow applicable BOD 22-01 guidance for cloud services. Discontinue use of the product if mitigations are unavailable.

If you can't patch immediately

Segment n8n deployments from other systems and restrict network access to the minimum required. Monitor workflow logs for signs of exploitation attempts. Discontinue the product where compensating controls cannot be implemented.

If your data may have been exposed

Actively exploited vulnerabilities lead to breaches. The reader can run a free exposure scan of their email to check known breach data.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

Affectedn8n · n8n
WeaknessCWE-913
Added to CISA KEVMar 11, 2026
Federal patch deadlineMar 25, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities