ACVE-2026-0557
Any user who can edit n8n workflows can run arbitrary code as the n8n process through a workflow expression on n8n 0.211.0 to before 1.120.4, and 1.121.0; exploited in the wild.
Exposure
Reproducibility: partial (vulnerable components are not confirmed obtainable; trigger not published)
Claims
Confirmed means the statement matches the cited primary source. Nothing on this page has been reproduced.
| Claim | Status | Source | Checked |
|---|---|---|---|
| Identifier CVE-2025-68613 | Confirmed | cveawg.mitre.org | 2026-09-25 |
| Identifier GHSA-v98v-ff95-f3cp | Confirmed | api.osv.dev | 2026-09-25 |
| Fixed in 1.120.4 | Confirmed | api.osv.dev | 2026-09-25 |
| Fixed in 1.121.1 | Confirmed | api.osv.dev | 2026-09-25 |
| Affected version below fixed 1.120.4 could not be checked from npm | Unconfirmed | registry.npmjs.org | |
| Upgrade target 1.122.0 | Confirmed | registry.npmjs.org | 2026-09-25 |
| Severity CRITICAL (CVSS 9.9); matches CNA | Confirmed | cveawg.mitre.org | 2026-09-25 |
In the wild
exploited-itw · kev
Description
What
n8n's workflow expression evaluation could run expressions that authenticated users supply while configuring a workflow in a context not sufficiently isolated from the underlying runtime, so a user who can create or edit workflows could run arbitrary code with the privileges of the n8n process and fully compromise the instance. Affected: 0.211.0 to before 1.120.4, and 1.121.0. Akamai's SIRT saw the Mirai-based Zerobot botnet attempting to exploit it in its honeypots in mid-January 2026, and CISA added it to KEV on 2026-03-11.
Detection
acve lock does not inventory n8n deployments, so this record has no matcher: check the installed n8n package version or the Docker image tag by hand.
Fix
Upgrade to 1.122.0, or to 1.120.4 or 1.121.1 on those release lines. Until then, n8n advises limiting workflow creation and editing to fully trusted users and running n8n with restricted operating-system privileges and network access; it says neither fully removes the risk.
Fix
Upgrade n8n to 1.122.0, or to 1.120.4 or 1.121.1 on those release lines.
- Upgrade
npm:n8nto1.122.0. The version n8n's advisory names; 1.120.4 and 1.121.1 also carry the fix (GHSA-v98v-ff95-f3cp). Owner: operator - Reconfigure
n8n.workflow-permissionstoworkflow creation and editing limited to fully trusted users. n8n's interim workaround until the upgrade; its advisory says it does not fully remove the risk. Owner: operator
References
ADVISORY
FIX
- https://github.com/n8n-io/n8n/commit/08f332015153decdda3c37ad4fcb9f7ba13a7c79
- https://github.com/n8n-io/n8n/commit/1c933358acef527ff61466e53268b41a04be1000
- https://github.com/n8n-io/n8n/commit/39a2d1d60edde89674ca96dcbb3eb076ffff6316