Vulnerabilities · 187 days ago

CISA Orders Patch for n8n RCE Exposing Workflow Secrets

CISA ordered federal agencies to patch an actively exploited n8n remote code execution flaw (CVE-2025-68613). The vulnerability lets authenticated attackers run code as the n8n process and risks exposure of API keys, database credentials, OAuth tokens, and CI/CD secrets held in workflows. Apply n8n

CVE-2025-68613

NVD KEV

Known exploited · CISA KEV

CVSS 9.9 CRITICAL: n8n is an open source workflow automation platform. EPSS 99% (100th percentile).

CISA federal remediation date Mar 25

Timeline

Sources

2 sources covering this story

Entities

Part of the PlainSec briefing for 2026-03-25

Editions

Related stories