
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68668 is a critical sandbox bypass vulnerability in the Python Code Node of n8n, an open-source workflow automation platform, that allows authenticated users to execute arbitrary commands on the host system. It affects n8n versions 1.0.0 through 1.x (before 2.0.0) running on Node.js. The vulnerability was published on December 24, 2025, and disclosed publicly on December 26, 2025. It carries a CVSS v3.1 base score of 9.9 (Critical) (Github Advisory, n8n Advisory).
The root cause is classified as CWE-693 (Protection Mechanism Failure): the Python Code Node uses Pyodide — a WebAssembly-based Python runtime — as a sandbox, but this sandbox can be bypassed by a sufficiently crafted Python payload (Github Advisory). An authenticated attacker with workflow creation or modification permissions can craft a malicious Python script within the Code Node that escapes the Pyodide sandbox and executes arbitrary OS-level commands with the same privileges as the n8n process (CAPEC-237: Escaping a Sandbox by Calling Code in Another Language) (n8n Advisory). The attack requires only low privileges (a valid n8n account with workflow edit access), no user interaction, and is exploitable remotely over the network with low complexity. A technical write-up detailing the sandbox escape mechanism is publicly available (SmartKeyss, Cyera Research).
Successful exploitation grants an attacker arbitrary command execution on the host system running n8n, with the full privileges of the n8n process — potentially including read/write access to the filesystem, environment variables, credentials, and connected services (n8n Advisory). The changed scope (S:C) in the CVSS vector indicates that the impact extends beyond the n8n application itself to the underlying host, enabling lateral movement, data exfiltration, and full system compromise (Github Advisory). Given that n8n is commonly integrated with databases, cloud services, and internal APIs, a compromised instance could serve as a pivot point into broader organizational infrastructure (Rapid7, Field Effect).
As of the time of disclosure, no confirmed in-the-wild exploitation has been reported, though the Shadowserver Foundation noted scanning activity targeting n8n instances (Shadowserver). A public technical write-up describing the Pyodide sandbox escape technique exists (SmartKeyss, Cyera Research), and exploit references have appeared on Sploitus (Sploitus). The EPSS score is approximately 0.10% (low near-term exploitation probability), and the vulnerability is not currently listed in the CISA KEV catalog. Qualys has added detection for this CVE (detection ID 733562) (Qualys). Researchers estimate over 100,000 n8n instances may be exposed, increasing the attack surface significantly (Hawk-Eye).
ctypes, cffi, or other low-level mechanisms to invoke system calls or load native libraries outside the Pyodide sandbox boundary./bin/sh, bash, curl, wget, python3) on the host system; unusual outbound network connections initiated by the n8n process.The definitive fix is to upgrade n8n to version 2.0.0 or later, which defaults to the task-runner-based native Python sandbox that provides proper isolation (n8n Advisory). For deployments that cannot immediately upgrade, three workarounds are available: (1) disable the Code Node entirely by setting NODES_EXCLUDE: '["n8n-nodes-base.code"]'; (2) disable Python support specifically by setting N8N_PYTHON_ENABLED=false (available since v1.104.0); or (3) enable the more secure task-runner-based Python sandbox by configuring N8N_RUNNERS_ENABLED and N8N_NATIVE_PYTHON_RUNNER environment variables (available since v1.111.0). Additionally, organizations should restrict workflow creation and modification permissions to trusted users only, and audit existing workflows for suspicious Python Code Node usage (Github Advisory, Qualys).
The vulnerability received significant media coverage under the nickname "ni8mare" (alongside related n8n flaws), with The Hacker News, CSO Online, Heise, and SentinelOne all publishing coverage (The Hacker News, CSO Online). Rapid7 published a detailed emergency threat response covering CVE-2025-68668 alongside related n8n vulnerabilities, highlighting the risk to self-hosted automation infrastructure (Rapid7). Security researcher Bruce Schneier noted the vulnerability on his blog, and the Belgian Centre for Cybersecurity issued an advisory urging immediate patching (Schneier, CCB Belgium). The Shadowserver Foundation reported active scanning of n8n instances following disclosure, and the vulnerability trended in CVEWatch communities for multiple weeks (Shadowserver).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."