CVE-2025-68697: 
NixOS vulnerability analysis and mitigation

Overview

CVE-2025-68697 is a privilege escalation vulnerability in self-hosted n8n instances where the Code node operates in legacy (non-task-runner) JavaScript execution mode. Authenticated users with workflow editing access can invoke internal helper functions from within the Code node, enabling arbitrary file read and write operations on the host filesystem with the same privileges as the n8n process. The vulnerability affects n8n versions >= 1.2.1 and < 2.0.0 (npm package). It was disclosed on December 24, 2025, and published to the GitHub Advisory Database on December 26, 2025. The CVSS v3.1 base score is 7.1 (High) per the GitHub Security Advisory, though NVD records a score of 5.4 (Medium) (GitHub Advisory, n8n Advisory).

Technical details

The root cause is classified under CWE-269 (Improper Privilege Management) and CWE-749 (Exposed Dangerous Method or Function). In the legacy Code node execution mode, n8n exposes internal helper functions to the JavaScript sandbox without adequate access controls, allowing authenticated workflow editors to call these functions directly. This bypasses the intended isolation boundary between user-supplied workflow code and the n8n host process. Starting with version 1.2.1, access to the .n8n home directory is blocked by default, but no broader filesystem restrictions are applied unless explicitly configured via environment variables such as N8N_RESTRICT_FILE_ACCESS_TO. A technical write-up detailing VM2 isolation bypass via exposed global helpers was published by the reporter (Medium Write-up, GitHub Advisory).

Impact

Successful exploitation allows an authenticated workflow editor to read and write arbitrary files on the n8n host filesystem, subject only to OS/container-level permissions of the n8n process. This can lead to exfiltration of sensitive configuration files, credentials, or application data stored on the host, as well as unauthorized modification of files that could facilitate persistence or further compromise. While availability is not directly impacted, the combination of file read and write access creates significant risk for data theft and system integrity compromise in self-hosted deployments (GitHub Advisory, Rapid7 Blog).

Exploitability

No public exploit code or active in-the-wild exploitation has been confirmed as of the available data. The EPSS score is approximately 0.017% (4th percentile), indicating a low near-term exploitation probability. The vulnerability requires authenticated access with workflow editing privileges, which limits the attack surface to trusted-but-malicious insiders or compromised accounts. CVE-2025-68697 is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The vulnerability was reported by researcher berkdedekarginoglu and is part of a broader set of n8n vulnerabilities analyzed by Rapid7 under the campaign names "ni8mare" and "n8scape" (GitHub Advisory, Rapid7 Blog).

Exploitation steps

  1. Gain authenticated access: Obtain credentials for an n8n account with workflow editing privileges on a self-hosted instance running n8n >= 1.2.1 and < 2.0.0 with the legacy Code node execution mode enabled (i.e., N8N_RUNNERS_ENABLED is not set to true).
  2. Create or edit a workflow: Log into the n8n web interface and create a new workflow or edit an existing one that includes a Code node.
  3. Invoke internal helper functions: Within the Code node's JavaScript editor, craft a payload that calls exposed internal n8n helper functions (e.g., filesystem access utilities) that are accessible in the legacy execution context but not intended for user use.
  4. Read sensitive files: Use the exposed functions to read arbitrary files from the host filesystem (e.g., environment files, SSH keys, application secrets) that the n8n process has permission to access, excluding .n8n directory contents (blocked by default since v1.2.1).
  5. Write malicious files: Optionally, write files to the host filesystem (e.g., web shells, cron jobs, or modified configuration files) to establish persistence or escalate further.
  6. Exfiltrate data: Return file contents as workflow output or exfiltrate via HTTP request nodes within the same workflow (GitHub Advisory, Medium Write-up).

Indicators of compromise

  • Logs: n8n application logs showing Code node executions that invoke filesystem-related internal functions; unusual workflow execution patterns from accounts not typically running Code nodes.
  • File System: Unexpected new files or modifications to files in directories accessible by the n8n process (e.g., /tmp, application directories, home directories); presence of web shells or scripts in locations writable by the n8n service account.
  • Network: Outbound HTTP requests from the n8n process to external IPs immediately following Code node execution, potentially indicating data exfiltration via workflow HTTP nodes.
  • Process: Unusual child processes spawned by the n8n Node.js process; file access patterns inconsistent with normal n8n operation visible in OS audit logs (e.g., auditd on Linux).

Mitigation and workarounds

The primary fix is to upgrade to n8n version 2.0.0 or later, where task runners are enabled by default for Code node execution, eliminating the legacy execution mode. For instances running n8n >= 1.71.0 that cannot immediately upgrade to 2.0.0, enable task runners by setting the environment variable N8N_RUNNERS_ENABLED=true. As interim workarounds: restrict filesystem access by setting N8N_RESTRICT_FILE_ACCESS_TO to a dedicated, non-sensitive directory; ensure N8N_BLOCK_FILE_ACCESS_TO_N8N_FILES=true remains set (the default); and if workflow editors are not fully trusted, disable the Code node entirely using the NODES_EXCLUDE environment variable (GitHub Advisory, n8n Advisory).

Community reactions

Rapid7 published a threat intelligence report covering CVE-2025-68697 as part of a broader analysis of multiple critical n8n vulnerabilities, dubbed "ni8mare" and "n8scape," highlighting the risk to self-hosted deployments (Rapid7 Blog). The original reporter, berkdedekarginoglu, published a technical write-up on Medium detailing the VM2 isolation bypass mechanism (Medium Write-up). The CISA vulnerability bulletin for the week of December 22, 2025 included this CVE, indicating government-level awareness of the issue (CISA Bulletin).

Additional resources


Source: This report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103678HIGH8.1
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103680MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103679MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103497MEDIUM5.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesOct 01, 2026
CVE-2026-103496MEDIUM5.4
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management