Historical catalog analysis: CISA added this entry on March 11, 2026. The entry reflects catalog information retrieved on August 31, 2026, not a snapshot archived on the inclusion date. Check current vendor guidance before acting.
What the vulnerability is
CVE-2025-68613 is an improper control of dynamically managed code resources vulnerability (CWE-913) identified in n8n. The flaw resides within the workflow expression evaluation system, which can be leveraged to achieve remote code execution (RCE).
Exposure and applicability
This vulnerability affects organizations deploying n8n for workflow automation. Because the issue is rooted in how the application evaluates expressions within its workflows, any instance utilizing this system may be exposed. Infrastructure owners should identify all active n8n deployments—including those hosted in cloud environments—to determine their susceptibility to RCE.
Remediation priorities
Based on our analysis of the reported vulnerability, we recommend the following prioritization for vulnerability management teams:
- Immediate Vendor Mitigation: Prioritize the application of mitigations as specified by n8n vendor instructions. This is the primary method for reducing the RCE exposure.
- Cloud Service Review: For organizations utilizing cloud-hosted versions of the service, review configurations against BOD 22-01 guidance to ensure that the shared responsibility model is addressed and provider-side mitigations are active.
- Service Decommissioning: In scenarios where vendor mitigations cannot be applied or are unavailable for a specific deployment architecture, the product should be discontinued to eliminate the risk of execution.
How to validate remediation
Verification must go beyond a simple version check. To ensure exposure is actually reduced, defenders should:
* Confirm Mitigation Application: Verify that the specific configuration changes or patches mandated by the vendor have been successfully deployed across all nodes.
* Functional Testing: In a staged environment, verify that the workflow expression evaluation system no longer permits the execution of unauthorized code resources as defined in the vulnerability report.
* Configuration Audit: For cloud deployments, validate that the security controls aligned with BOD 22-01 are active and enforced by the service provider.
Limits and open questions
It remains unknown whether this vulnerability has been utilized in known ransomware campaigns. Furthermore, while vendor mitigations reduce risk, residual risk may persist if the underlying workflow logic allows for other forms of injection or if the environment lacks sufficient runtime isolation (such as containerization) to limit the impact of a potential breakout. The effectiveness of these mitigations depends entirely on strict adherence to the vendor’s specific implementation instructions.
Source and editorial note
CVE-2025-68613: n8n Improper Control of Dynamically-Managed Code Resources Vulnerability · Source date: March 11, 2026 · Retrieved August 31, 2026.
Material facts are tied to the cited primary source. Recommendations are independent defensive analysis unless attributed to the source. Confirm consequential decisions against current authoritative guidance.
Archive date: March 14, 2026. The displayed post date is assigned three days after the source date to organize this retrospective archive; it does not mean this site published the analysis then. First published by this site: September 18, 2026 at 00:44 UTC.
Request a Vulnerability Assessment
Turn security intelligence into action.
Discuss your exposure, priorities, and the evidence needed to validate the outcome.
Request a security assessment ↗