Critical n8n Vulnerability Allows Command Execution by Authenticated Users

Critical n8n Vulnerability Allows Command Execution by Authenticated Users

First seen 6 Jan 2026, 16:41 UTC ThehackernewsCybersecuritynewsGbhackers 46.0

Article Content

Browse articles
ThreatCluster

A critical vulnerability in n8n, an open-source workflow automation platform, has been identified, allowing authenticated attackers to execute arbitrary commands on host systems. This vulnerability, tracked as CVE-2025-68668, has a CVSS score of 9.9 out of 10, indicating its severe impact. The issue is related to a sandbox-bypass flaw in n8n's Python environment.