# CISA Adds Actively Exploited n8n Remote Code Execution Flaw to Catalog as Thousands Remain Vulnerable
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has officially added a critical remote code execution vulnerability in n8n to its Known Exploited Vulnerabilities (KEV) catalog, confirming that threat actors are actively leveraging the flaw in real-world attacks. The development underscores an urgent risk for organizations relying on the popular open-source workflow automation platform, with security researchers estimating approximately 24,700 publicly accessible instances currently exposed to exploitation.
The vulnerability, tracked as CVE-2025-68613, carries a CVSS severity score of 9.9—the highest rating on the common vulnerability scoring system—and permits unauthenticated remote attackers to execute arbitrary code on vulnerable servers with minimal interaction. The confirmation of active exploitation combined with the staggering number of exposed instances has elevated this from a standard security advisory to a critical threat requiring immediate organizational response.
## Understanding n8n and Its Attack Surface
n8n is a free and open-source workflow automation platform that enables organizations to connect and automate thousands of applications without extensive coding. The tool has gained substantial adoption across enterprises, startups, and mid-market organizations seeking to streamline repetitive processes, integrate disparate systems, and reduce manual intervention in business operations. Its popularity stems from flexibility, ease of deployment, and a growing ecosystem of pre-built connectors.
However, this widespread deployment creates a significant attack surface. Organizations deploying n8n instances—whether in cloud environments, containerized infrastructure, or on-premises servers—may inadvertently expose critical automation capabilities to internet-facing attack vectors. For threat actors, compromised n8n instances represent particularly valuable targets, as these systems typically possess broad integration capabilities and elevated permissions across connected business applications.
## The Vulnerability in Detail
CVE-2025-68613 stems from insufficient input validation in n8n's workflow execution engine. The flaw allows attackers to craft specially malformed requests that bypass authentication and authorization controls, ultimately leading to unauthenticated remote code execution on the underlying host system.
An attacker exploiting this vulnerability requires no prior authentication credentials and no user interaction from the target organization. A single HTTP request containing malicious payload is sufficient to execute arbitrary commands with the privileges of the n8n process—typically possessing significant access to integrated systems and data stores.
The particular severity of this flaw reflects both its technical impact and practical exploitability. Organizations running vulnerable n8n versions can be compromised within seconds of an instance becoming internet-accessible, whether through misconfigured cloud deployments, insecure reverse proxy setups, or intentional exposure for remote access purposes.
## Active Exploitation and CISA Response
CISA's addition of CVE-2025-68613 to the Known Exploited Vulnerabilities catalog signals that federal cybersecurity authorities have confirmed evidence of active exploitation in the wild. This designation carries significant weight within government security directives and influences procurement requirements for federal contractors and critical infrastructure organizations.
Intelligence indicates that threat actors have developed and deployed exploit code targeting the vulnerability across multiple attack campaigns. Security telemetry suggests initial reconnaissance activity preceded by automated scanning aimed at identifying publicly accessible n8n instances. Once discovered, targeted instances are rapidly compromised and leveraged for follow-on malicious activities including data exfiltration, lateral movement, and deployment of persistent backdoors.
## The Exposed Instance Problem
The discovery of approximately 24,700 publicly accessible n8n instances without proper network access controls represents the central operational security challenge surrounding this vulnerability. Shodan searches and Internet-wide scanning have identified instances exposing the web interface to unrestricted public access, many running vulnerable versions lacking available security patches.
This number reflects a troubling pattern within cloud-native deployments: organizations implementing workflow automation platforms without implementing robust network segmentation, authentication hardening, or monitoring controls. In many cases, instances were deliberately exposed for remote access convenience without implementing compensating security measures such as VPN gateways, IP allowlisting, or Web Application Firewalls.
## Threat Model and Attack Scenarios
Compromise of n8n instances creates multiple attack pathways for adversaries. Initial foothold establishment through RCE provides shell access to the underlying system, enabling threat actors to:
## Defensive Recommendations for Organizations
Security teams managing n8n deployments should immediately implement the following protective measures:
Immediate Actions (24-48 hours)
Short-term Mitigation (1-2 weeks)
Long-term Hardening
## Industry and Vendor Response
The n8n development team has released patches addressing CVE-2025-68613 in recent stable releases. Organizations remain responsible for deploying patches across their deployed instances—a responsibility often complicated by operational dependencies and integration testing requirements. Security teams should establish upgrade timelines reflecting vulnerability criticality balanced against operational risk tolerance.
Third-party security vendors have released detection signatures and threat intelligence feeds enabling identification of exploitation attempts. Organizations should integrate these indicators into their security information and event management platforms and network intrusion detection systems.
## HackWire Analysis
CVE-2025-68613 exemplifies a recurring vulnerability class in modern infrastructure: critical flaws in widely-deployed but often-neglected internal tools. Organizations readily patch customer-facing applications while automation platforms receive less security attention despite possessing extensive internal system access.
The 24,700 exposed instances suggests significant organizational blind spots regarding asset visibility and network security fundamentals. This number likely understates true vulnerability scope—many additional instances remain hidden behind network address translation or operate in segmented networks unindexed by public scanning.
The key lesson for security practitioners is straightforward: automation platforms command trust within organizations because they execute with elevated privileges. That trust demands corresponding security rigor. CVE-2025-68613 should trigger comprehensive audits of all internally-focused tooling—not merely remediation of this single flaw, but architectural re-evaluation of which systems truly require internet accessibility and what authentication and authorization safeguards protect them.