CVE-2025-68613 Security Alert: CRITICAL Vulnerability

Urgent: CVE-2025-68613 requires immediate attention.

· 3 min read

```html

Executive Summary

A critical Remote Code Execution (RCE) vulnerability has been identified in npm n8n affecting versions prior to 1.122.0. This vulnerability allows authenticated attackers to execute arbitrary code within the context of the n8n process, potentially leading to full compromise of affected instances. Immediate action is required to mitigate risks associated with this vulnerability.

Immediate Action

  • Upgrade to n8n v1.122.0 or later immediately.
  • Limit workflow creation and editing permissions to trusted users only.
  • Deploy n8n in a hardened environment with restricted OS privileges and network access.
  • Regularly review and audit your n8n workflows for unauthorized changes.
  • Monitor for updates and advisories from the n8n team. [Vendor Advisory Link]

Affected Versions

  • n8n@<=1.121.9 vulnerable; upgrade to 1.122.0+

Resolution Guide

To upgrade n8n, use one of the following commands:

npm install n8n@1.122.0

For users of Yarn:

yarn add n8n@1.122.0

For Docker users, ensure you pull the latest image:

docker pull n8nio/n8n:latest

To harden your n8n configuration, consider the following example:

const options = {
    // Disable specific features temporarily
    disableFeatureX: true,
};

Ensure your environment variables are set to limit permissions:

export N8N_USER=trusted_user
export N8N_WORKFLOW_PERMISSIONS=read-only

Detection & Verification

To check if your current version of n8n is vulnerable, run:

npm list n8n

To verify you have upgraded successfully, use:

npm list n8n | grep n8n

Ensure the output reflects version 1.122.0 or later.

Risk and Impact

The exploitation of CVE-2025-68613 could allow an authenticated attacker to execute arbitrary code, leading to unauthorized access to sensitive data, modification of workflows, and execution of system-level operations. The potential blast radius includes total compromise of the n8n instance and all workflows, posing significant risks to data integrity and confidentiality.

```

Keep reading