← advisory ledger

ADVISORY UNAUTH-2026-0042
TYPE cve
PRODUCT n8n
SEVERITY CRITICAL

CRITICAL

n8n CVE-2025-68613

published 2026-08-05 · updated 2026-08-05

Why it matters

Authenticated RCE via expression injection: the {{ }} expression sandbox fails to isolate execution, letting any user with workflow edit rights reach process.mainModule and run system commands as the n8n process. Actively exploited (CISA KEV). CVSS 9.9.

Affected versions

  • >=0.211.0,<1.120.4
  • ==1.121.0

Fixed in: 1.120.4 / 1.121.1 / 1.122.0

Mapping provenance: human-verified against the linked advisory, last checked 2026-07-29. CISA KEV listed as actively exploited.

Fix it

Fix card: cve-2025-68613 →

References

Cite this record

unauth.dev advisory UNAUTH-2026-0042 — published 2026-08 · CC-BY 4.0

Canonical URL: https://unauth.dev/advisories/UNAUTH-2026-0042. This record is part of the unauth.dev advisory dataset, published under CC-BY 4.0: attribute "unauth.dev / Raúl Acedo". Schema: additive-only within v1; this id will never be renumbered or reused.