{
  "schema_version": "1.6.0",
  "id": "ACVE-2026-0557",
  "aliases": [
    "CVE-2025-68613",
    "GHSA-v98v-ff95-f3cp"
  ],
  "published": "2025-12-19T00:00:00Z",
  "firstReported": {
    "date": "2025-12-19",
    "url": "https://github.com/n8n-io/n8n/security/advisories/GHSA-v98v-ff95-f3cp",
    "publisher": "n8n (GitHub advisory)"
  },
  "modified": "2026-09-25T00:00:00Z",
  "summary": "Any user who can edit n8n workflows can run arbitrary code as the n8n process through a workflow expression on n8n 0.211.0 to before 1.120.4, and 1.121.0; exploited in the wild.",
  "details": "## What\n\nn8n's workflow expression evaluation could run expressions that authenticated users supply while configuring a workflow in a context not sufficiently isolated from the underlying runtime, so a user who can create or edit workflows could run arbitrary code with the privileges of the n8n process and fully compromise the instance. Affected: 0.211.0 to before 1.120.4, and 1.121.0. Akamai's SIRT saw the Mirai-based Zerobot botnet attempting to exploit it in its honeypots in mid-January 2026, and CISA added it to KEV on 2026-03-11.\n\n## Detection\n\n`acve lock` does not inventory n8n deployments, so this record has no matcher: check the installed `n8n` package version or the Docker image tag by hand.\n\n## Fix\n\nUpgrade to 1.122.0, or to 1.120.4 or 1.121.1 on those release lines. Until then, n8n advises limiting workflow creation and editing to fully trusted users and running n8n with restricted operating-system privileges and network access; it says neither fully removes the risk.",
  "severity": [
    {
      "type": "CVSS_V3",
      "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
    }
  ],
  "affected": [
    {
      "package": {
        "ecosystem": "npm",
        "name": "n8n",
        "purl": "pkg:npm/n8n"
      },
      "ranges": [
        {
          "type": "SEMVER",
          "events": [
            {
              "introduced": "0.211.0"
            },
            {
              "fixed": "1.120.4"
            },
            {
              "introduced": "1.121.0"
            },
            {
              "fixed": "1.121.1"
            }
          ]
        }
      ]
    }
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://github.com/n8n-io/n8n/security/advisories/GHSA-v98v-ff95-f3cp"
    },
    {
      "type": "ADVISORY",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-68613"
    },
    {
      "type": "FIX",
      "url": "https://github.com/n8n-io/n8n/commit/08f332015153decdda3c37ad4fcb9f7ba13a7c79"
    },
    {
      "type": "FIX",
      "url": "https://github.com/n8n-io/n8n/commit/1c933358acef527ff61466e53268b41a04be1000"
    },
    {
      "type": "FIX",
      "url": "https://github.com/n8n-io/n8n/commit/39a2d1d60edde89674ca96dcbb3eb076ffff6316"
    },
    {
      "type": "REPORT",
      "url": "https://www.akamai.com/blog/security-research/2026/feb/zerobot-malware-targets-n8n-automation-platform"
    },
    {
      "type": "WEB",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-68613"
    }
  ],
  "database_specific": {
    "severity": "CRITICAL",
    "acve": {
      "specVersion": 1,
      "status": "candidate",
      "kind": "code",
      "vulnClasses": [
        "sandbox-escape"
      ],
      "cwe": [
        "CWE-913"
      ],
      "exposure": {
        "harness": {
          "value": "n8n 0.211.0 to before 1.120.4, and 1.121.0",
          "any": false,
          "status": "confirmed",
          "source": "https://cveawg.mitre.org/api/cve/CVE-2025-68613"
        },
        "model": {
          "value": "any",
          "any": true,
          "status": "confirmed",
          "source": "https://cveawg.mitre.org/api/cve/CVE-2025-68613"
        },
        "goal": {
          "value": "Any workflow that an authenticated user configures",
          "stated": false,
          "status": "unconfirmed"
        },
        "tools": {
          "value": "Workflow expressions supplied by authenticated users during workflow configuration, evaluated by the workflow expression evaluation system",
          "status": "confirmed",
          "source": "https://cveawg.mitre.org/api/cve/CVE-2025-68613"
        },
        "approval": {
          "value": "Only an authenticated user who can configure workflows is needed; the expression is evaluated without sufficient isolation from the runtime",
          "mode": "none-required",
          "status": "confirmed",
          "source": "https://cveawg.mitre.org/api/cve/CVE-2025-68613"
        },
        "inputControl": "unknown",
        "agentAction": "n8n evaluates the user-supplied expression outside a sufficiently isolated context and runs the attacker's code with the privileges of the n8n process.",
        "harm": "arbitrary-command",
        "divergence": "none"
      },
      "exploitation": {
        "status": "exploited-itw",
        "checkedAt": "2026-09-25T00:00:00Z",
        "sources": [
          {
            "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-68613",
            "type": "kev",
            "note": "Added 2026-03-11, due 2026-03-25 (KEV JSON catalog 2026.09.25)."
          },
          {
            "url": "https://www.akamai.com/blog/security-research/2026/feb/zerobot-malware-targets-n8n-automation-platform",
            "type": "research",
            "note": "Akamai SIRT (2026-02-27) saw the Mirai-based Zerobot botnet attempting to exploit CVE-2025-68613 in its honeypots in mid-January 2026."
          }
        ],
        "kev": {
          "listed": true,
          "date_added": "2026-03-11",
          "due_date": "2026-03-25"
        }
      },
      "taxonomy": {
        "owasp_asi": [
          "ASI05"
        ],
        "atlas": [
          "AML.T0049",
          "AML.T0012"
        ]
      },
      "cveBoundary": "cve-aliased",
      "fix": {
        "summary": "Upgrade n8n to 1.122.0, or to 1.120.4 or 1.121.1 on those release lines.",
        "actions": [
          {
            "type": "upgrade",
            "target": "npm:n8n",
            "to": "1.122.0",
            "why": "The version n8n's advisory names; 1.120.4 and 1.121.1 also carry the fix (GHSA-v98v-ff95-f3cp).",
            "owner": "operator"
          },
          {
            "type": "reconfigure",
            "target": "n8n.workflow-permissions",
            "to": "workflow creation and editing limited to fully trusted users",
            "why": "n8n's interim workaround until the upgrade; its advisory says it does not fully remove the risk.",
            "owner": "operator"
          }
        ]
      },
      "claims": [
        {
          "kind": "identifier",
          "statement": "Identifier CVE-2025-68613",
          "value": "CVE-2025-68613",
          "status": "confirmed",
          "source": "https://cveawg.mitre.org/api/cve/CVE-2025-68613",
          "result": "match",
          "observed": "CVE.org: PUBLISHED",
          "method": "machine",
          "checkedAt": "2026-09-25T18:36:14Z"
        },
        {
          "kind": "identifier",
          "statement": "Identifier GHSA-v98v-ff95-f3cp",
          "value": "GHSA-v98v-ff95-f3cp",
          "status": "confirmed",
          "source": "https://api.osv.dev/v1/vulns/GHSA-v98v-ff95-f3cp",
          "result": "match",
          "observed": "OSV: record found",
          "method": "machine",
          "checkedAt": "2026-09-25T18:36:14Z"
        },
        {
          "kind": "fixed-version",
          "statement": "Fixed in 1.120.4",
          "value": "1.120.4",
          "status": "confirmed",
          "source": "https://api.osv.dev/v1/vulns/GHSA-v98v-ff95-f3cp",
          "result": "match",
          "observed": "OSV: fixed 1.120.4; fixed 1.121.1; CVE.org structured: affected-version >= 0.211.0, < 1.120.4; affected-version = 1.121.0; CVE.org description: fixed 1.120.4; npm: version exists",
          "method": "machine",
          "checkedAt": "2026-09-25T18:36:14Z"
        },
        {
          "kind": "fixed-version",
          "statement": "Fixed in 1.121.1",
          "value": "1.121.1",
          "status": "confirmed",
          "source": "https://api.osv.dev/v1/vulns/GHSA-v98v-ff95-f3cp",
          "result": "match",
          "observed": "OSV: fixed 1.120.4; fixed 1.121.1; CVE.org structured: affected-version >= 0.211.0, < 1.120.4; affected-version = 1.121.0; CVE.org description: fixed 1.120.4; npm: version exists",
          "method": "machine",
          "checkedAt": "2026-09-25T18:36:14Z"
        },
        {
          "kind": "installable",
          "statement": "Affected version below fixed 1.120.4 could not be checked from npm",
          "value": "1.120.4",
          "status": "unconfirmed",
          "source": "https://registry.npmjs.org/n8n",
          "result": "unchecked",
          "observed": "registry.npmjs.org: unchecked",
          "method": "machine"
        },
        {
          "kind": "fixed-version",
          "statement": "Upgrade target 1.122.0",
          "value": "1.122.0",
          "status": "confirmed",
          "source": "https://registry.npmjs.org/n8n/1.122.0",
          "result": "match",
          "observed": "npm: version exists",
          "method": "machine",
          "checkedAt": "2026-09-25T18:36:14Z"
        },
        {
          "kind": "severity",
          "statement": "Severity CRITICAL (CVSS 9.9); matches CNA",
          "value": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
          "status": "confirmed",
          "source": "https://cveawg.mitre.org/api/cve/CVE-2025-68613",
          "observed": "CNA: CRITICAL 10 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H); OSV: CRITICAL 9.9 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H); OSV: CRITICAL 9.9 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)",
          "result": "match",
          "method": "machine",
          "checkedAt": "2026-09-25T18:36:14Z"
        }
      ],
      "severityBasis": "cvss",
      "reproducibility": {
        "status": "partial",
        "axesComplete": true,
        "componentsObtainable": null,
        "triggerPublished": false,
        "observableStated": true,
        "demonstrated": "vendor-confirmed",
        "missing": [
          "vulnerable components are not confirmed obtainable",
          "trigger not published"
        ]
      }
    }
  }
}
