ACVEAgent configuration vulnerability registry

ACVE-2026-0557

Any user who can edit n8n workflows can run arbitrary code as the n8n process through a workflow expression on n8n 0.211.0 to before 1.120.4, and 1.121.0; exploited in the wild.

Exposure

Reproducibility: partial (vulnerable components are not confirmed obtainable; trigger not published)

Claims

Confirmed means the statement matches the cited primary source. Nothing on this page has been reproduced.

ClaimStatusSourceChecked
Identifier CVE-2025-68613Confirmedcveawg.mitre.org2026-09-25
Identifier GHSA-v98v-ff95-f3cpConfirmedapi.osv.dev2026-09-25
Fixed in 1.120.4Confirmedapi.osv.dev2026-09-25
Fixed in 1.121.1Confirmedapi.osv.dev2026-09-25
Affected version below fixed 1.120.4 could not be checked from npmUnconfirmedregistry.npmjs.org
Upgrade target 1.122.0Confirmedregistry.npmjs.org2026-09-25
Severity CRITICAL (CVSS 9.9); matches CNAConfirmedcveawg.mitre.org2026-09-25

In the wild

exploited-itw · kev

Description

What

n8n's workflow expression evaluation could run expressions that authenticated users supply while configuring a workflow in a context not sufficiently isolated from the underlying runtime, so a user who can create or edit workflows could run arbitrary code with the privileges of the n8n process and fully compromise the instance. Affected: 0.211.0 to before 1.120.4, and 1.121.0. Akamai's SIRT saw the Mirai-based Zerobot botnet attempting to exploit it in its honeypots in mid-January 2026, and CISA added it to KEV on 2026-03-11.

Detection

acve lock does not inventory n8n deployments, so this record has no matcher: check the installed n8n package version or the Docker image tag by hand.

Fix

Upgrade to 1.122.0, or to 1.120.4 or 1.121.1 on those release lines. Until then, n8n advises limiting workflow creation and editing to fully trusted users and running n8n with restricted operating-system privileges and network access; it says neither fully removes the risk.

Fix

Upgrade n8n to 1.122.0, or to 1.120.4 or 1.121.1 on those release lines.

  • Upgrade npm:n8n to 1.122.0. The version n8n's advisory names; 1.120.4 and 1.121.1 also carry the fix (GHSA-v98v-ff95-f3cp). Owner: operator
  • Reconfigure n8n.workflow-permissions to workflow creation and editing limited to fully trusted users. n8n's interim workaround until the upgrade; its advisory says it does not fully remove the risk. Owner: operator

References

ADVISORY

FIX

WEB

Report a problemJSON