#VU120269 Improper Control of Dynamically-Managed Code Resources in n8n - CVE-2025-68613
Published: December 23, 2025 / Updated: February 27, 2026
n8n
n8n
Description
The vulnerability allows a remote user to compromise the affected system.
The vulnerability exists due to an error within the workflow expression evaluation system. A remote authenticated user can supply a specially crafted workflow configuration that can be evaluated in an execution context that is not sufficiently isolated from the underlying runtime, leading to privilege escalation.