Intel

AIKIDO-2025-10969

n8n is vulnerable to Remote Code Execution via Expression Injection

Remote Code Execution via Expression InjectionCVE-2025-68613 Published Dec 22, 2025

99

Critical Risk

This Affects:

JSn8n
0.211.0 - 1.120.3
Fixed in 1.120.4
1.121.0 - 1.121.0
Fixed in 1.121.1
Are you affected? Scan for Free

TL;DR

Affected versions of n8n are vulnerable to remote code execution due to expression injection in the workflow expression evaluation system, where expressions provided by authenticated users during workflow configuration may be evaluated in an insufficiently isolated execution context, allowing an attacker to execute arbitrary code with the privileges of the n8n process and potentially fully compromise the instance, access sensitive data, modify workflows, or perform system-level operations; this issue is fixed in n8n v1.122.0, and users should upgrade immediately, while temporary mitigations include restricting workflow creation and editing to fully trusted users and running n8n in a hardened environment, noting that these measures do not fully eliminate the risk.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

n8n is vulnerable to Remote Code Execution via Expression Injection in versions 0.211.0 - 1.120.3 and 1.121.0 - 1.121.0.

How to fix this

Upgrade the n8n library to the patch version.