目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2025-68613— n8n 安全漏洞

一分钟漏洞结论

影响对象
n8n-io n8n
利用判断
已确认在野利用,应立即处置
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

n8n是n8n开源的一个可扩展的工作流自动化工具。 n8n 0.211.0版本至1.120.4版本、1.121.1版本和1.122.0版本之前版本存在安全漏洞,该漏洞源于工作流表达式评估系统隔离不足,可能导致远程代码执行。

CVSS 10.0 · Critical KEV EPSS 98.99% · P100
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2025-68613 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
n8n Vulnerable to Remote Code Execution via Expression Injection
来源: CVE Program / CVE List V5
Vulnerability Description
n8n is an open source workflow automation platform. Versions starting with 0.211.0 and prior to 1.120.4, 1.121.1, and 1.122.0 contain a critical Remote Code Execution (RCE) vulnerability in their workflow expression evaluation system. Under certain conditions, expressions supplied by authenticated users during workflow configuration may be evaluated in an execution context that is not sufficiently isolated from the underlying runtime. An authenticated attacker could abuse this behavior to execute arbitrary code with the privileges of the n8n process. Successful exploitation may lead to full compromise of the affected instance, including unauthorized access to sensitive data, modification of workflows, and execution of system-level operations. This issue has been fixed in versions 1.120.4, 1.121.1, and 1.122.0. Users are strongly advised to upgrade to a patched version, which introduces additional safeguards to restrict expression evaluation. If upgrading is not immediately possible, administrators should consider the following temporary mitigations: Limit workflow creation and editing permissions to fully trusted users only; and/or deploy n8n in a hardened environment with restricted operating system privileges and network access to reduce the impact of potential exploitation. These workarounds do not fully eliminate the risk and should only be used as short-term measures.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
来源: CVE Program / CVE List V5
Vulnerability Type
动态管理代码资源的控制不恰当
来源: CVE Program / CVE List V5
Vulnerability Title
n8n 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
n8n是n8n开源的一个可扩展的工作流自动化工具。 n8n 0.211.0版本至1.120.4版本、1.121.1版本和1.122.0版本之前版本存在安全漏洞,该漏洞源于工作流表达式评估系统隔离不足,可能导致远程代码执行。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

神龙十问 — AI 深度分析

十问解析:根本原因、利用方式、修复建议、紧迫性。摘要免费,完整版需登录。

受影响产品

厂商 产品 影响版本 CPE 订阅
n8n-io n8n >= 0.211.0, < 1.120.4 -

二、漏洞 CVE-2025-68613 的公开POC

# POC 描述 源链接 神龙链接
1 Detection for CVE-2025-68613 https://github.com/rxerium/CVE-2025-68613 POC详情
2 CVE-2025-68613 https://github.com/Ashwesker/Blackash-CVE-2025-68613 POC详情
3 Public PoC + Scanner and research for CVE-2025-68613: Critical RCE in n8n Workflow Automation via Expression Injection (CVSS 10.0). Includes detection tools, full exploit, and remediation guidance. https://github.com/TheStingR/CVE-2025-68613-POC POC详情
4 CVE-2025-68613: n8n RCE vulnerability exploit and documentation https://github.com/wioui/n8n-CVE-2025-68613-exploit POC详情
5 通过GitHub Copilot 辅助分析CVE-2025-68613漏洞 https://github.com/intbjw/CVE-2025-68613-poc-via-copilot POC详情
6 None https://github.com/ali-py3/Exploit-CVE-2025-68613 POC详情
7 This repository contains a laboratory-grade analysis and a **safe Proof-of-Concept** for the vulnerability **CVE-2025-68613**, affecting the workflow automation platform **n8n**. https://github.com/nehkark/CVE-2025-68613 POC详情
8 My poc to exploit this vuln :D https://github.com/GnuTLam/POC-CVE-2025-68613 POC详情
9 n8n < 1.120.4, 1.121.1, 1.122.0 contains a remote code execution caused by insufficient isolation in workflow expression evaluation, letting authenticated attackers execute arbitrary code with n8n process privileges. Exploit requires authentication. https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-68613.yaml POC详情
10 基于Pocsuite3 框架编写的漏洞验证与利用脚本,用于检测 n8n工作流自动化工具中的认证后远程代码执行漏洞(RCE) https://github.com/secjoker/CVE-2025-68613 POC详情
11 Analysis of CVE-2025-68613 https://github.com/r4j3sh-com/CVE-2025-68613-n8n-lab POC详情
12 None https://github.com/intelligent-ears/CVE-2025-68613 POC详情
13 GUI Shodan-powered scanner to identify n8n instances exposed to CVE-2025-68613 (version range 0.211.0–1.122.0) https://github.com/manyaigdtuw/CVE-2025-68613_Scanner POC详情
14 Remote Code Execution via n8n Workflows (Based on CVE-2025-68613) https://github.com/AbdulRKB/n8n-RCE POC详情
15 Python Exploit for CVE-2025-68613. https://github.com/JohannesLks/CVE-2025-68613-Python-Exploit POC详情
16 n8n God Mode Ultimate - CVE-2025-68613 Scanner v1.0.0 ║ ║ Workflow Automation Remote Code Execution https://github.com/hackersatyamrastogi/n8n-exploit-CVE-2025-68613-n8n-God-Mode-Ultimate POC详情
17 Proof-of-Concept exploit for CVE-2025-68613: Authenticated Remote Code Execution in n8n via Expression Injection https://github.com/mbanyamer/n8n-Authenticated-Expression-Injection-RCE-CVE-2025-68613 POC详情
18 Technical study of the CVE-2025-68613 vulnerability in n8n, covering affected versions, laboratory exploration scenario, offensive and defensive analysis, and mitigation strategies. https://github.com/releaseown/Analysis-n8n-CVE-2025-68613 POC详情
19 None https://github.com/Dlanang/homelab-CVE-2025-68613 POC详情
20 None https://github.com/Khin-96/n8n-cve-2025-68613-thm POC详情
21 The minor methodology for room: https://tryhackme.com/room/n8ncve202568613 https://github.com/J4ck3LSyN-Gen2/n8n-CVE-2025-68613-TryHackMe POC详情
22 CVE-2025-68613 (n8n) Critical RCE analysis + defensive recommendations (patch validation, detection ideas, and hardening tips) https://github.com/Ak-cybe/CVE-2025-68613-n8n-rce-analysis POC详情
23 This laboratory provides a controlled environment to analyze and reproduce CVE-2025-68613 in a vulnerable n8n instance. https://github.com/LingerANR/n8n-CVE-2025-68613 POC详情
24 POC for CVE-2025-68613 https://github.com/reem-012/poc_CVE-2025-68613 POC详情
25 Technical study of the CVE-2025-68613 vulnerability in n8n, covering affected versions, laboratory exploration scenario, offensive and defensive analysis, and mitigation strategies. https://github.com/releaseown/analysis-and-poc-n8n-CVE-2025-68613 POC详情
26 n8n CVE-2025-68613 https://github.com/gagaltotal/n8n-cve-2025-68613 POC详情
27 CVE-2025-68613 https://github.com/Ashwesker/Ashwesker-CVE-2025-68613 POC详情
28 None https://github.com/cv-sai-kamesh/n8n-CVE-2025-68613 POC详情
29 n8n RCE (CVE-2025-68613) - Proof of Concept https://github.com/ahmedshamsddin/n8n-RCE-CVE-2025-68613 POC详情
30 Expression injection payloads for n8n CVE-2025-68613 RCE https://github.com/TheInterception/n8n_CVE-2025-68613_exploit_payloads POC详情
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2025-68613 的情报信息

请登录查看更多情报信息。

CVE-2025-68613 补丁与修复 (3)

IV. Related Vulnerabilities

V. Comments for CVE-2025-68613

暂无评论


发表评论