Source: The Hacker News
Author: info@thehackernews.com (The Hacker News)
URL: https://thehackernews.com/2025/12/critical-n8n-flaw-cvss-99-enables.html
ONE SENTENCE SUMMARY:
A critical vulnerability in n8n could allow arbitrary code execution, affecting many global instances, and requiring urgent patch updates.
MAIN POINTS:
- The vulnerability in n8n has a CVSS score of 9.9.
- It was discovered by security researcher Fatih Çelik.
- The issue affects versions from 0.211.0 to below 1.120.4.
- Exploitation allows attackers to execute arbitrary code.
- Successful attacks can compromise the entire n8n instance.
- Over 103,476 instances are potentially vulnerable.
- Instances are primarily in the U.S., Germany, France, Brazil, and Singapore.
- The flaw has been patched in versions 1.120.4, 1.121.1, and 1.122.0.
- Users must update immediately to protect their systems.
- Temporary mitigation includes restricting user permissions and securing the environment.
TAKEAWAYS:
- Update n8n to a patched version immediately.
- Recognize the high severity of CVE-2025-68613.
- Limit workflow permissions to trusted users only.
- Deploy n8n in a secure, isolated environment.
- Stay informed about global instances that might be at risk.