CVE-2025-68613
n8n expression sandbox escape allows authenticated remote code execution
- Severity
- critical
- Affected product
- n8n
- Affected versions
- n8n < 1.123.22
- Affected versions
- n8n ≥ 2.0.0, < 2.9.3
- Affected versions
- n8n ≥ 2.10.0, < 2.10.1
- Fixed in
- n8n 1.123.22
- Fixed in
- n8n 2.9.3
- Fixed in
- n8n 2.10.1
- Added to NewScan
- 2026-08-10
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints n8n from its response and reports this CVE when the detected version falls inside the affected range below.
Range taken from the VENDOR advisory GHSA-vpcf-gvg4-6qwr, which says affected `< 1.123.22, >= 2.0.0 < 2.9.3, >= 2.10.0 < 2.10.1` - NOT the 0.211.0-1.120.3 range the vulhub write-up quotes. This row is the 1.x branch; the two 2.x branches are separate rows because the pack's range matcher takes one interval per row. Proof pair: affected = vulhub n8n/CVE-2025-68613 (1.65.0), fixed = training/good/n8n (2.29.9).
COMPONENT VERSION RANGE
NewScan fingerprints n8n from its response and reports this CVE when the detected version falls inside the affected range below.
The 2.0.x-2.9.x branch of GHSA-vpcf-gvg4-6qwr. See the 1.x row for the full affected set.
COMPONENT VERSION RANGE
NewScan fingerprints n8n from its response and reports this CVE when the detected version falls inside the affected range below.
The 2.10.x branch of GHSA-vpcf-gvg4-6qwr. See the 1.x row for the full affected set.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →