
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68697 is a privilege escalation vulnerability in self-hosted n8n instances where the Code node operates in legacy (non-task-runner) JavaScript execution mode. Authenticated users with workflow editing access can invoke internal helper functions from within the Code node, enabling arbitrary file read and write operations on the host filesystem with the same privileges as the n8n process. The vulnerability affects n8n versions >= 1.2.1 and < 2.0.0 (npm package). It was disclosed on December 24, 2025, and published to the GitHub Advisory Database on December 26, 2025. The CVSS v3.1 base score is 7.1 (High) per the GitHub Security Advisory, though NVD records a score of 5.4 (Medium) (GitHub Advisory, n8n Advisory).
The root cause is classified under CWE-269 (Improper Privilege Management) and CWE-749 (Exposed Dangerous Method or Function). In the legacy Code node execution mode, n8n exposes internal helper functions to the JavaScript sandbox without adequate access controls, allowing authenticated workflow editors to call these functions directly. This bypasses the intended isolation boundary between user-supplied workflow code and the n8n host process. Starting with version 1.2.1, access to the .n8n home directory is blocked by default, but no broader filesystem restrictions are applied unless explicitly configured via environment variables such as N8N_RESTRICT_FILE_ACCESS_TO. A technical write-up detailing VM2 isolation bypass via exposed global helpers was published by the reporter (Medium Write-up, GitHub Advisory).
Successful exploitation allows an authenticated workflow editor to read and write arbitrary files on the n8n host filesystem, subject only to OS/container-level permissions of the n8n process. This can lead to exfiltration of sensitive configuration files, credentials, or application data stored on the host, as well as unauthorized modification of files that could facilitate persistence or further compromise. While availability is not directly impacted, the combination of file read and write access creates significant risk for data theft and system integrity compromise in self-hosted deployments (GitHub Advisory, Rapid7 Blog).
No public exploit code or active in-the-wild exploitation has been confirmed as of the available data. The EPSS score is approximately 0.017% (4th percentile), indicating a low near-term exploitation probability. The vulnerability requires authenticated access with workflow editing privileges, which limits the attack surface to trusted-but-malicious insiders or compromised accounts. CVE-2025-68697 is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The vulnerability was reported by researcher berkdedekarginoglu and is part of a broader set of n8n vulnerabilities analyzed by Rapid7 under the campaign names "ni8mare" and "n8scape" (GitHub Advisory, Rapid7 Blog).
N8N_RUNNERS_ENABLED is not set to true)..n8n directory contents (blocked by default since v1.2.1)./tmp, application directories, home directories); presence of web shells or scripts in locations writable by the n8n service account.The primary fix is to upgrade to n8n version 2.0.0 or later, where task runners are enabled by default for Code node execution, eliminating the legacy execution mode. For instances running n8n >= 1.71.0 that cannot immediately upgrade to 2.0.0, enable task runners by setting the environment variable N8N_RUNNERS_ENABLED=true. As interim workarounds: restrict filesystem access by setting N8N_RESTRICT_FILE_ACCESS_TO to a dedicated, non-sensitive directory; ensure N8N_BLOCK_FILE_ACCESS_TO_N8N_FILES=true remains set (the default); and if workflow editors are not fully trusted, disable the Code node entirely using the NODES_EXCLUDE environment variable (GitHub Advisory, n8n Advisory).
Rapid7 published a threat intelligence report covering CVE-2025-68697 as part of a broader analysis of multiple critical n8n vulnerabilities, dubbed "ni8mare" and "n8scape," highlighting the risk to self-hosted deployments (Rapid7 Blog). The original reporter, berkdedekarginoglu, published a technical write-up on Medium detailing the VM2 isolation bypass mechanism (Medium Write-up). The CISA vulnerability bulletin for the week of December 22, 2025 included this CVE, indicating government-level awareness of the issue (CISA Bulletin).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."