Known vulnerability record
CVE-2025-68613
n8n Improper Control of Dynamically-Managed Code Resources Vulnerability
Summary
n8n Improper Control of Dynamically-Managed Code Resources Vulnerability
n8n contains an improper control of dynamically managed code resources vulnerability in its workflow expression evaluation system that allows for remote code execution.
Signals
Keep the signals separate
CVSS severitycriticalScore 10 · source GitHub_M
EPSS probability98.0%Probability of exploitation in the next 30 days; not severity
CISA KEVKnown exploitedAdded 2026-03-11
Ransomware useunknownPreserved as known / unknown, not a truthy default
Timeline
Dates and provenance
- CVE published
- 2025-12-19
- CVE modified
- 2026-03-12
- KEV date added
- 2026-03-11
- Dataset fetched
- 2026-08-21T03:55:07.778Z
Sources
Original records
- https://www.cve.org/CVERecord?id=CVE-2025-68613 ↗
- https://nvd.nist.gov/vuln/detail/CVE-2025-68613 ↗
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-68613 ↗
Version history: normalized permanent page created 2026-08-20. Machine-enriched fields remain source-attributed.