CVE-2025-68613: n8n Improper Control of Dynamically-Managed Code Resources Vulnerability
n8n contains an improper control of dynamically managed code resources vulnerability in its workflow expression evaluation system that allows for remote code execution.
n8n contains an improper control of dynamically managed code resources vulnerability in its workflow expression evaluation system that allows for remote code execution.
Organizations running n8n for automation should treat this as a priority because successful exploitation can grant attackers the ability to run arbitrary code on the affected system.
How it works
The flaw is categorized under CWE-913. It stems from insufficient restrictions on dynamically managed code resources within the workflow expression evaluation system, enabling an attacker to supply input that results in remote code execution.
Am I affected? How to find it in your systems
n8n is a workflow automation platform commonly deployed in cloud or self-hosted environments. Begin by locating all n8n instances through asset inventories, container registries, or orchestration platforms.
- Review configurations that involve expression evaluation or dynamic code handling.
- Confirm exact affected versions and settings against the vendor advisory, as public detail is limited.
- Examine workflow execution logs for anomalous patterns that could indicate attempts to manipulate code resources.
How to remediate
Apply mitigations per vendor instructions. Follow applicable BOD 22-01 guidance for cloud services. Discontinue use of the product if mitigations are unavailable.
If you can't patch immediately
Segment n8n deployments from other systems and restrict network access to the minimum required. Monitor workflow logs for signs of exploitation attempts. Discontinue the product where compensating controls cannot be implemented.
If your data may have been exposed
Actively exploited vulnerabilities lead to breaches. The reader can run a free exposure scan of their email to check known breach data.
AICompiled with AI assistance from public sources and published under our editorial standards.