Vulnerabilità · 201 giorni fa

CISA Orders Patch for n8n RCE Exposing Workflow Secrets

CISA ordered federal agencies to patch an actively exploited n8n remote code execution flaw (CVE-2025-68613). The vulnerability lets authenticated attackers run code as the n8n process and risks exposure of API keys, database credentials, OAuth tokens, and CI/CD secrets held in workflows. Apply n8n

CVE-2025-68613

NVD KEV

Sfruttamento noto · CISA KEV

CVSS 9.9 CRITICAL: n8n is an open source workflow automation platform. EPSS 99% (100º percentile).

Data di correzione federale CISA 25 mar

Cronologia

Fonti

2 fonti che coprono questa storia

Entità

Part of the PlainSec briefing for 2026-03-25

Editions

Storie correlate