HomeSecurityNew vulnerability in n8n allows arbitrary command execution

New vulnerability in n8n allows arbitrary command execution

A new critical security vulnerability has been disclosed in n8n, an open-source workflow automation platform. The vulnerability could allow an authorized attacker to execute arbitrary system on the underlying host.

vulnerability in n8n

The vulnerability, tracked as CVE-2025-68668, has been rated 9.9 on the CVSS scoring system and is described as a failure protection mechanism.

See also: AdonisJS Bodyparser: Critical vulnerability allows writing files to the server

It affects versions 1.0.0 through 2.0.0 (the latter is not affected), allowing an authorized user with permissions to create or modify workflows to execute arbitrary operating system on the host computer running n8n. The issue has been addressed in version 2.0.0.

“ A sandbox bypass vulnerability exists in the Python Code Node that Pyodide uses ,” an advisory for the bug states . “ An authorized user with permissions to create or modify workflows could exploit this vulnerability to execute arbitrary commands on the hosting system running n8n, using the same privileges as the n8n process .”

See also: Eaton vulnerabilities allow malicious code to run on the system

New vulnerability in n8n allows arbitrary command execution

n8n: Improved protection

n8n introduced a native task runner-based Python implementation in version 1.111.0, as an optional feature for improved security isolation. This feature can be enabled by configuring the environment variables Ν8N_RUNNERS_ENABLED and Ν8N_NATIVE_PYTHON_RUNNER. With the release of version 2.0.0 , the implementation has become the default.

Alternative solutions: Users are also invited to follow these steps:

– Disable Code Node by setting the environment variable NODES_EXCLUDE: “[\”n8n-nodes-base.code\”]”

– Disable Python support in Code node by setting the environment variable Ν8N_PYTHON_ENABLED=false

– Configure N8N to use the task runner-based Python sandbox via the N8N_RUNNERS_ENABLED and N8N_NATIVE_PYTHON_RUNNER environment variables

See also: Zero-day vulnerabilities: Why they're on the rise and who pays the price

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS