The US Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that hackers are exploiting a max-severity remote code execution (RCE) vulnerability in workflow automation platform n8n. CISA urged all federal civilian executive branch (FCEB) agencies to patch CVE-2025-68613 at once because it carries a near-perfect 9.9 vulnerability score. The bug was first disclosed in December, and vendors such as Resecurity said that of n8n's roughly 230,000 active users, more than 103,000 appeared to be vulnerable. CVE-2025-68613 can lead to RCE on the open source workflow automation platform, with potential consequences ranging from simple data theft to full-blown supply chain compromise. The vulnerability affects n8n and its expression evaluation engine, which are commonly used to automate operational tasks across systems. n8n's advisory states that, under certain conditions, authenticated attackers can inject payloads into expressions that are then executed without validation. "Successful exploitation may lead to full compromise of the affected instance, including unauthorized access to sensitive data, modification of workflows, and execution of system-level operations," it said. In plain terms, it means that an attacker with access to a low-privilege account could assume control of the entire n8n instance and abuse it to potentially access secrets such as passwords or push malicious code by modifying workflows, among other nastiness. n8n patched the bug in v1.122.0, but g...
CISA warns max-severity n8n bug is being exploited in the wild
The Register
·Connor Jones
·Published Mar 12, 2026
·Updated
Affected Software
1 affected component
n8n workflow automation platform<1.122.0
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a max-severity remote code execution vulnerability in the n8n workflow automation platform that is currently being exploited by hackers.
2
What security implications are discussed in the article?
The article highlights the risk of unauthorized access and control of systems using the n8n platform due to the remote code execution vulnerability.
3
What products or software are affected by the vulnerability?
The affected product is the n8n workflow automation platform, specifically versions up to 1.122.0.
4
What actions does CISA recommend for organizations using n8n?
CISA urges all federal civilian executive branch departments and agencies to take immediate action to mitigate the vulnerability.
5
How critical is the n8n vulnerability mentioned in the article?
The n8n vulnerability is classified as max-severity, indicating a high level of risk and urgency to address it.