CVE-2025-68613 Security Alert: CRITICAL Vulnerability
Urgent: CVE-2025-68613 requires immediate attention.
· 3 min read
```htmlExecutive Summary
A critical Remote Code Execution (RCE) vulnerability has been identified in npm n8n affecting versions prior to 1.122.0. This vulnerability allows authenticated attackers to execute arbitrary code within the context of the n8n process, potentially leading to full compromise of affected instances. Immediate action is required to mitigate risks associated with this vulnerability.
Immediate Action
- Upgrade to
n8n v1.122.0or later immediately. - Limit workflow creation and editing permissions to trusted users only.
- Deploy n8n in a hardened environment with restricted OS privileges and network access.
- Regularly review and audit your n8n workflows for unauthorized changes.
- Monitor for updates and advisories from the n8n team. [Vendor Advisory Link]
Affected Versions
n8n@<=1.121.9vulnerable; upgrade to1.122.0+
Resolution Guide
To upgrade n8n, use one of the following commands:
npm install n8n@1.122.0
For users of Yarn:
yarn add n8n@1.122.0
For Docker users, ensure you pull the latest image:
docker pull n8nio/n8n:latest
To harden your n8n configuration, consider the following example:
const options = {
// Disable specific features temporarily
disableFeatureX: true,
};
Ensure your environment variables are set to limit permissions:
export N8N_USER=trusted_user
export N8N_WORKFLOW_PERMISSIONS=read-only
Detection & Verification
To check if your current version of n8n is vulnerable, run:
npm list n8n
To verify you have upgraded successfully, use:
npm list n8n | grep n8n
Ensure the output reflects version 1.122.0 or later.
Risk and Impact
The exploitation of CVE-2025-68613 could allow an authenticated attacker to execute arbitrary code, leading to unauthorized access to sensitive data, modification of workflows, and execution of system-level operations. The potential blast radius includes total compromise of the n8n instance and all workflows, posing significant risks to data integrity and confidentiality.
```