CVE-2025-68613HIGH 8.8CISA KEVEPSS p99.9%
CVE-2025-68613n8n Improper Control of Dynamically-Managed Code Resources Vulnerability
n8n / n8n
Description
n8n contains an improper control of dynamically managed code resources vulnerability in its workflow expression evaluation system that allows for remote code execution.
Scoring
| CVSS 3.1 | 8.8 (HIGH) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 98.01% probability of exploitation · percentile 99.9% · 2026-06-15T12:03:41Z |
| Published | 2025-12-19 |
| Last modified | 2026-03-11 |
CISA KEV entry
Added to KEV: 2026-03-11
Underlying weaknesses· 1
References
- https://github.com/n8n-io/n8n/commit/08f332015153decdda3c37ad4fcb9f7ba13a7c79
- https://github.com/n8n-io/n8n/commit/1c933358acef527ff61466e53268b41a04be1000
- https://github.com/n8n-io/n8n/commit/39a2d1d60edde89674ca96dcbb3eb076ffff6316
- https://github.com/n8n-io/n8n/security/advisories/GHSA-v98v-ff95-f3cp
- https://www.akamai.com/blog/security-research/2026/feb/zerobot-malware-targets-n8n-automation-platform
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-68613
1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Improper Control of Dynamically-Managed Code Resourcescwe-913 | 0% | live |
(incoming)1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| KEVEntry | n8n Improper Control of Dynamically-Managed Code Resources Vulnerabilitykev-cve-2025-68613 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.