Critical 9.9
KEV-listed
CVE-2025-68613
CVE-2025-68613 Exploited in n8n
Vendor / product: n8n
Event date: 2026-03-11
Public PoC: Yes
First tracked by RiskWire: 2026-07-28
CISA KEV catalog
Added to KEV
Federal remediation due
2026-03-25 (179 days overdue)
Ransomware campaign use
Unknown
CISA description
n8n contains an improper control of dynamically managed code resources vulnerability in its workflow expression evaluation system that allows for remote code execution.
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Sources & citations (3)
- Leaked n8n API Tokens Exposed Live Instances to Credential Theft thehackernews.com · 2026-08-05
- Leaked n8n API Tokens: 321 Live Instances Exposed blog.gridinsoft.com · 2026-08-05
- No Hack Required: How Thousands of Leaked API Tokens Left Automation Servers Wide Open ibtimes.sg · 2026-08-06
References
See CVE-2025-68613 in context
RiskWire tracks every exploited CVE this week, cross-referenced against CISA KEV with federal remediation deadlines. Filtered to your vendor stack.
Book a 20-min demo →