What happened
n8n contains an improper control of dynamically managed code resources vulnerability in its workflow expression evaluation system that allows for remote code execution.
Affected versions
n8n: See original advisory Fixed: See vendor advisory.
Why it matters
This source correlation may provide earlier visibility while structured CVE metadata is still being updated.
Detection & mitigation
- Review the original advisory and validate affected versions.
- Apply vendor-provided updates or mitigations when available.
Public PoC references
RepositoryAuthorFirst seenReference
SploitusUnauthenticated RCE in n8n via file read and expression injection sandbox bypass.ZeroDayEvil2026-09-12T00:10:10VerifiedPoC-in-GitHub · ZeroDayEvil/CVE-2026-21858-n8n-FullChain🛡️ Official AI Security Tool module for CVE-2026-21858 + CVE-2025-68613 (n8n "Ni8mare" Unauthenticated Arbitrary File Read & Expression Injection RCE Full Chain).★ 0ZeroDayEvil2026-09-12CandidatePoC-in-GitHub · rxerium/CVE-2025-68613Detection for CVE-2025-68613★ 28rxerium2025-12-22CandidatePoC-in-GitHub · TheStingR/CVE-2025-68613-POCPublic PoC + Scanner and research for CVE-2025-68613: Critical RCE in n8n Workflow Automation via Expression Injection (CVSS 10.0). Includes detection tools, full exploit, and remediation guidance.★ 29TheStingR2025-12-22CandidatePoC-in-GitHub · sahilccras/Blackash-CVE-2025-68613CVE-2025-68613★ 0sahilccras2025-12-22CandidatePoC-in-GitHub · wioui/n8n-CVE-2025-68613-exploitCVE-2025-68613: n8n RCE vulnerability exploit and documentation★ 106wioui2025-12-22CandidatePoC-in-GitHub · reem-012/poc_CVE-2025-68613POC for CVE-2025-68613★ 0reem-0122025-12-23CandidatePoC-in-GitHub · intbjw/CVE-2025-68613-poc-via-copilot通过GitHub Copilot 辅助分析CVE-2025-68613漏洞★ 0intbjw2025-12-23CandidatePoC-in-GitHub · ali-py3/Exploit-CVE-2025-68613★ 0ali-py32025-12-23CandidatePoC-in-GitHub · nehkark/CVE-2025-68613This repository contains a laboratory-grade analysis and a **safe Proof-of-Concept** for the vulnerability **CVE-2025-68613**, affecting the workflow automation platform **n8n**.★ 0nehkark2025-12-23CandidatePoC-in-GitHub · GnuTLam/POC-CVE-2025-68613My poc to exploit this vuln :D★ 0GnuTLam2025-12-23CandidatePoC-in-GitHub · secjoker/CVE-2025-68613基于Pocsuite3 框架编写的漏洞验证与利用脚本,用于检测 n8n工作流自动化工具中的认证后远程代码执行漏洞(RCE)★ 0secjoker2025-12-24CandidatePoC-in-GitHub · r4j3sh-com/CVE-2025-68613-n8n-labAnalysis of CVE-2025-68613★ 0r4j3sh-com2025-12-24CandidatePoC-in-GitHub · intelligent-ears/CVE-2025-68613★ 0intelligent-ears2025-12-24CandidatePoC-in-GitHub · manyaigdtuw/CVE-2025-68613_ScannerGUI Shodan-powered scanner to identify n8n instances exposed to CVE-2025-68613 (version range 0.211.0–1.122.0)★ 0manyaigdtuw2025-12-24CandidatePoC-in-GitHub · AbdulRKB/n8n-RCEProof of Concept (PoC) Script for Remote Code Execution via n8n Workflows (Based on CVE-2025-68613)★ 0AbdulRKB2025-12-25CandidatePoC-in-GitHub · JohannesLks/CVE-2025-68613-Python-ExploitPython Exploit for CVE-2025-68613.★ 1JohannesLks2025-12-25CandidatePoC-in-GitHub · hackersatyamrastogi/n8n-exploit-CVE-2025-68613-n8n-God-Mode-Ultimaten8n God Mode Ultimate - CVE-2025-68613 Scanner v1.0.0 ║ ║ Workflow Automation Remote Code Execution★ 5hackersatyamrastogi2025-12-25CandidatePoC-in-GitHub · mbanyamer/n8n-Authenticated-Expression-Injection-RCE-CVE-2025-68613Proof-of-Concept exploit for CVE-2025-68613: Authenticated Remote Code Execution in n8n via Expression Injection★ 2mbanyamer2025-12-25CandidatePoC-in-GitHub · releaseown/analysis-and-poc-n8n-CVE-2025-68613Technical study of the CVE-2025-68613 vulnerability in n8n, covering affected versions, laboratory exploration scenario, offensive and defensive analysis, and mitigation strategies.★ 1releaseown2025-12-25CandidatePoC-in-GitHub · Dlanang/homelab-CVE-2025-68613★ 0Dlanang2025-12-26CandidatePoC-in-GitHub · Khin-96/n8n-cve-2025-68613-thm★ 1Khin-962025-12-26CandidatePoC-in-GitHub · J4ck3LSyN-Gen2/n8n-CVE-2025-68613-TryHackMeThe minor methodology for room: https://tryhackme.com/room/n8ncve202568613★ 0J4ck3LSyN-Gen22025-12-26CandidatePoC-in-GitHub · Ak-cybe/CVE-2025-68613-n8n-rce-analysisCVE-2025-68613 (n8n) Critical RCE analysis + defensive recommendations (patch validation, detection ideas, and hardening tips)★ 1Ak-cybe2025-12-26CandidatePoC-in-GitHub · LingerANR/n8n-CVE-2025-68613This laboratory provides a controlled environment to analyze and reproduce CVE-2025-68613 in a vulnerable n8n instance.★ 7LingerANR2025-12-26CandidatePoC-in-GitHub · gagaltotal/n8n-cve-2025-68613n8n CVE-2025-68613★ 0gagaltotal2025-12-28CandidatePoC-in-GitHub · cv-sai-kamesh/n8n-CVE-2025-68613★ 0cv-sai-kamesh2025-12-29CandidatePoC-in-GitHub · Rishi-kaul/n8n-CVE-2025-68613★ 0Rishi-kaul2025-12-29CandidatePoC-in-GitHub · ahmedshamsddin/n8n-RCE-CVE-2025-68613n8n RCE (CVE-2025-68613)★ 0ahmedshamsddin2026-01-03CandidatePoC-in-GitHub · TheInterception/n8n_CVE-2025-68613_exploit_payloadsExpression injection payloads for n8n CVE-2025-68613 RCE★ 0TheInterception2026-01-03CandidatePoC-in-GitHub · Victorhugofariasvieir66/relatorio-n8n.mdRelatório TryHackMe — n8n CVE-2025-68613 (CVSS 9.9)★ 0Victorhugofariasvieir662026-01-22CandidatePoC-in-GitHub · h3raklez/CVE-2025-68613CVE-2025-68613 — n8n RCE via Expression Injection★ 0h3raklez2026-03-03CandidatePoC-in-GitHub · canpilayda/n8n-RCE-CVE-2025-68613★ 0canpilayda2026-04-14CandidatePoC-in-GitHub · azilRababe/CVE-2025-68613Technical analysis of CVE-2025-68613, a critical Expression Injection vulnerability in n8n that allows authenticated attackers to achieve Remote Code Execution (RCE)★ 0azilRababe2026-06-21CandidatePoC-in-GitHub · qianlijaingshan/n8n-cve-2026-21858CVE-2026-21858 + CVE-2025-68613 — n8n unauthenticated file read to RCE exploit★ 0qianlijaingshan2026-07-21CandidatePoC-in-GitHub · Giangdurian/CVE-2026-21858-and-CVE-2025-68613★ 0Giangdurian2026-07-31CandidatePoC-in-GitHub · rmhowe425/POC-CVE-2025-68613★ 0rmhowe4252026-09-05CandidateSource timeline
Discovered through CISA Known Exploited VulnerabilitiesView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Record history
Record created from the first normalized source observation.
Metadata and source references refreshed.