Critical n8n RCE vulnerability enables full server compromise

A critical vulnerability (CVE-2025-68613, CVSS 9.9/10.0) was disclosed affecting the n8n workflow automation platform, allowing attackers to execute arbitrary code on the underlying server via expression injection in workflow definitions. Due to the potential for full instance takeover, data exposure, and lateral movement, immediate patching is required. The issue originates from n8n’s workflow expression evaluation … Continue reading Critical n8n RCE vulnerability enables full server compromise