CVE-2025-68668: 
NixOS vulnerability analysis and mitigation

Overview

CVE-2025-68668 is a critical sandbox bypass vulnerability in the Python Code Node of n8n, an open-source workflow automation platform, that allows authenticated users to execute arbitrary commands on the host system. It affects n8n versions 1.0.0 through 1.x (before 2.0.0) running on Node.js. The vulnerability was published on December 24, 2025, and disclosed publicly on December 26, 2025. It carries a CVSS v3.1 base score of 9.9 (Critical) (Github Advisory, n8n Advisory).

Technical details

The root cause is classified as CWE-693 (Protection Mechanism Failure): the Python Code Node uses Pyodide — a WebAssembly-based Python runtime — as a sandbox, but this sandbox can be bypassed by a sufficiently crafted Python payload (Github Advisory). An authenticated attacker with workflow creation or modification permissions can craft a malicious Python script within the Code Node that escapes the Pyodide sandbox and executes arbitrary OS-level commands with the same privileges as the n8n process (CAPEC-237: Escaping a Sandbox by Calling Code in Another Language) (n8n Advisory). The attack requires only low privileges (a valid n8n account with workflow edit access), no user interaction, and is exploitable remotely over the network with low complexity. A technical write-up detailing the sandbox escape mechanism is publicly available (SmartKeyss, Cyera Research).

Impact

Successful exploitation grants an attacker arbitrary command execution on the host system running n8n, with the full privileges of the n8n process — potentially including read/write access to the filesystem, environment variables, credentials, and connected services (n8n Advisory). The changed scope (S:C) in the CVSS vector indicates that the impact extends beyond the n8n application itself to the underlying host, enabling lateral movement, data exfiltration, and full system compromise (Github Advisory). Given that n8n is commonly integrated with databases, cloud services, and internal APIs, a compromised instance could serve as a pivot point into broader organizational infrastructure (Rapid7, Field Effect).

Exploitability

As of the time of disclosure, no confirmed in-the-wild exploitation has been reported, though the Shadowserver Foundation noted scanning activity targeting n8n instances (Shadowserver). A public technical write-up describing the Pyodide sandbox escape technique exists (SmartKeyss, Cyera Research), and exploit references have appeared on Sploitus (Sploitus). The EPSS score is approximately 0.10% (low near-term exploitation probability), and the vulnerability is not currently listed in the CISA KEV catalog. Qualys has added detection for this CVE (detection ID 733562) (Qualys). Researchers estimate over 100,000 n8n instances may be exposed, increasing the attack surface significantly (Hawk-Eye).

Exploitation steps

  1. Reconnaissance: Identify internet-facing n8n instances running versions 1.0.0–1.x using tools like Shodan or Censys, searching for the n8n web interface (default port 5678). Confirm the version is below 2.0.0.
  2. Authentication: Log in to the n8n instance using a valid low-privilege account that has permission to create or modify workflows.
  3. Create or modify a workflow: Navigate to the workflow editor and add or edit a Code Node configured to use Python (Pyodide mode).
  4. Inject sandbox escape payload: Insert a crafted Python script into the Code Node that exploits Pyodide's sandbox limitations to call host-level OS functions — for example, using Python's ctypes, cffi, or other low-level mechanisms to invoke system calls or load native libraries outside the Pyodide sandbox boundary.
  5. Execute the workflow: Trigger the workflow manually or via a webhook/schedule, causing the malicious Python code to execute on the host with the privileges of the n8n process.
  6. Achieve post-exploitation objectives: Use the gained code execution to establish a reverse shell, exfiltrate credentials or data, or pivot to connected services and internal infrastructure (n8n Advisory, SmartKeyss, Cyera Research).

Indicators of compromise

  • Logs: n8n application logs showing Python Code Node executions with unusual or obfuscated payloads; unexpected errors from the Pyodide runtime indicating sandbox boundary probing; workflow execution logs for newly created or recently modified workflows by non-admin users.
  • Process: Unexpected child processes spawned by the n8n Node.js process (e.g., /bin/sh, bash, curl, wget, python3) on the host system; unusual outbound network connections initiated by the n8n process.
  • Network: Outbound connections from the n8n host to unknown external IPs or C2 infrastructure, particularly on non-standard ports; DNS lookups for unfamiliar domains originating from the n8n server.
  • File System: New or modified files in the n8n working directory or system temp directories created by the n8n process; unexpected cron jobs, SSH authorized keys, or scripts added under the n8n service account's home directory.
  • Workflow Artifacts: Presence of Code Nodes using Python with obfuscated or encoded payloads in workflow definitions; workflows created or modified by accounts that do not normally use Python Code Nodes (Rapid7, LevelBlue).

Mitigation and workarounds

The definitive fix is to upgrade n8n to version 2.0.0 or later, which defaults to the task-runner-based native Python sandbox that provides proper isolation (n8n Advisory). For deployments that cannot immediately upgrade, three workarounds are available: (1) disable the Code Node entirely by setting NODES_EXCLUDE: '["n8n-nodes-base.code"]'; (2) disable Python support specifically by setting N8N_PYTHON_ENABLED=false (available since v1.104.0); or (3) enable the more secure task-runner-based Python sandbox by configuring N8N_RUNNERS_ENABLED and N8N_NATIVE_PYTHON_RUNNER environment variables (available since v1.111.0). Additionally, organizations should restrict workflow creation and modification permissions to trusted users only, and audit existing workflows for suspicious Python Code Node usage (Github Advisory, Qualys).

Community reactions

The vulnerability received significant media coverage under the nickname "ni8mare" (alongside related n8n flaws), with The Hacker News, CSO Online, Heise, and SentinelOne all publishing coverage (The Hacker News, CSO Online). Rapid7 published a detailed emergency threat response covering CVE-2025-68668 alongside related n8n vulnerabilities, highlighting the risk to self-hosted automation infrastructure (Rapid7). Security researcher Bruce Schneier noted the vulnerability on his blog, and the Belgian Centre for Cybersecurity issued an advisory urging immediate patching (Schneier, CCB Belgium). The Shadowserver Foundation reported active scanning of n8n instances following disclosure, and the vulnerability trended in CVEWatch communities for multiple weeks (Shadowserver).

Additional resources


Source: This report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103493HIGH8.1
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesOct 01, 2026
CVE-2026-103494MEDIUM6.6
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026
CVE-2026-103497MEDIUM5.5
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026
CVE-2026-103496MEDIUM5.4
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026
CVE-2026-103495MEDIUM4.3
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management