Threat reportVulnerabilityTL-2026-0226
n8n Workflow Automation RCE via Expression Injection — CVE-2025-68613 (CVSS 9.9) Active Exploitation by Zerobot Botnet
n8n Workflow Automation RCE via Expression Injection (TL-2026-0226), also tracked as GHSA-v98v-ff95-f3cp, is a critical-severity software vulnerability scored CVSS 9.9, first published 2026-03-14. It is attributed to Zerobot Botnet with medium confidence, affects n8n-io n8n, references 1 CVE (CVE-2025-68613), maps to 19 MITRE ATT&CK techniques (T1005, T1027, T1041), and is covered by 9 detection rules and 23 indicators of compromise.
- CVSS
- 9.9/10Critical
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 19MITRE ATT&CK
- Actors
- 1Zerobot Botnet
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 23Indicators of compromise
Key facts for TL-2026-0226
- Threat ID
- TL-2026-0226
- Also known as
- GHSA-v98v-ff95-f3cp
- Severity
- CRITICAL
- CVSS
- 9.9 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution
- Zerobot Botnet
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- technology, financial, healthcare, government, manufacturing, education, retail
- Target regions
- North America, Europe, Asia-Pacific, Global
- Detection rules
- 9
- Indicators of compromise
- 23
Malware and tooling in n8n Workflow Automation RCE via Expression Injection
Malware and tooling: zerobotv9, Mirai/Zerobot
How n8n Workflow Automation RCE via Expression Injection works
Critical RCE vulnerability (CVSS 9.9) in n8n workflow automation platform versions 0.211.0 through 1.120.3 and 1.121.0, actively exploited in the wild by the Zerobot botnet to deploy Mirai-variant malware. Insufficient sandbox isolation in the expression evaluation engine allows authenticated attackers to escape the JavaScript sandbox via Node.js this context and execute arbitrary OS commands. CISA added CVE-2025-68613 to the KEV catalog on March 11, 2026 with a federal patch deadline of March 25, 2026. Over 24,700 unpatched instances remain exposed globally.
CVE-2025-68613 is a critical Remote Code Execution vulnerability in n8n, a popular open-source workflow automation platform used by thousands of organizations for business process automation, data integration, and AI workflow orchestration.
The vulnerability resides in n8n's server-side expression evaluation engine, which processes JavaScript expressions wrapped in {{ }} delimiters within workflow node parameters. The core flaw is that the execution sandbox fails to properly isolate the evaluation context from the Node.js runtime. Specifically, the JavaScript this keyword within evaluated expressions exposes the Node.js global context, granting access to the process object. An attacker can leverage this to call process.mainModule.require('child_process').execSync() to execute arbitrary OS-level commands with the privileges of the n8n process.
The exploit chain is straightforward: 1. An authenticated user (no elevated privileges required) creates or modifies a workflow via the REST API (POST /rest/workflows) 2. A malicious expression is injected into a node parameter (typically using the n8n-nodes-base.set node type) 3. When the workflow is activated or executed, the expression evaluator processes the payload 4. The JavaScript escapes the sandbox via this.process.mainModule.require() 5. The child_process module is loaded and execSync() executes arbitrary commands
The canonical exploit payload is: {{ (function(){ return this.process.mainModule.require('child_process').execSync('COMMAND').toString() })() }}
Akamai's Security Intelligence and Response Team (SIRT) identified active exploitation by the Zerobot botnet beginning in mid-January 2026, with campaign activity traced back to December 2025. The botnet exploits CVE-2025-68613 to deploy a Mirai-based malware variant called zerobotv9, which supports multiple architectures (x86, MIPS, ARM, PPC). The initial infection vector uses a shell script (tol.sh) downloaded from 144.172.100.228 that fetches and executes architecture-specific zerobotv9 binaries. The C2 infrastructure operates via 0bot.qzz[.]io.
Shadowserver Foundation data from February 2026 shows 24,700+ unpatched n8n instances exposed globally, with 12,300+ in North America and 7,800+ in Europe. Censys reported 103,476 potentially vulnerable instances as of December 22, 2025. The EPSS score is 76.93% (99th percentile), indicating extremely high probability of exploitation.
The vulnerability was patched in December 2025 with versions 1.120.4, 1.121.1, and 1.122.0, which introduce additional safeguards to restrict expression evaluation and prevent sandbox escapes. A related vulnerability, CVE-2026-27577 (CVSS 9.4), was subsequently discovered by Pillar Security in the same expression evaluation system.
Organizations running self-hosted n8n instances must patch immediately or implement strict access controls to limit workflow creation and editing to trusted users only.
MITRE ATT&CK techniques used in TL-2026-0226
collection
defense-evasion
T1027 Obfuscated Files or Information; T1070 Indicator Removal; T1140 Deobfuscate/Decode Files or Information
exfiltration
T1041 Exfiltration Over C2 Channel
execution
T1053 Scheduled Task/Job; T1059 Command and Scripting Interpreter; T1203 Exploitation for Client Execution
privilege-escalation
T1068 Exploitation for Privilege Escalation
command-and-control
T1071 Application Layer Protocol; T1105 Ingress Tool Transfer; T1571 Non-Standard Port
discovery
T1082 System Information Discovery; T1083 File and Directory Discovery; T1087 Account Discovery
initial-access
T1190 Exploit Public-Facing Application
impact
persistence
T1505 Server Software Component
credential-access
Affected products and versions in n8n Workflow Automation RCE via Expression Injection
- n8n-io — n8n
Vulnerable versions: 0.211.0 through 1.120.3; 1.121.0
Fixed in: 1.120.4; 1.121.1; 1.122.0
Remediation for n8n Workflow Automation RCE via Expression Injection
Patches
- n8n v1.120.4 — backport fix for expression sandbox hardening
- n8n v1.121.1 — backport fix for expression sandbox hardening
- n8n v1.122.0 — primary fix release with enhanced expression evaluation safeguards
Immediate actions
- Upgrade n8n to version 1.120.4, 1.121.1, or 1.122.0+ immediately
- Block IOC IP addresses at network perimeter (144.172.100.228, 140.233.190.96, 172.86.123.179, 216.126.227.101, 103.59.160.237)
- Block C2 domain 0bot.qzz.io and malware distribution domains andro.notemacro.com, pivot.notemacro.com at DNS and proxy
- Restrict workflow creation and editing permissions to trusted users only
- Disable public registration on n8n instances
- Audit existing workflows for suspicious expressions containing process.mainModule or child_process references
Workarounds
- Restrict workflow creation/editing to fully trusted administrators only
- Disable n8n REST API access from untrusted networks
- Place n8n behind a reverse proxy with authentication and IP allowlisting
- Run n8n with minimal OS privileges and restricted filesystem access
- Monitor for expressions containing process, require, child_process, execSync in workflow definitions
Longer-term hardening
- Deploy n8n in hardened environments with restricted OS privileges — never run as root
- Implement network segmentation to isolate n8n instances from critical infrastructure
- Restrict outbound network connections from n8n to only required endpoints
- Enable comprehensive audit logging for workflow creation and modification
- Deploy EDR/XDR with behavioral detection for Node.js process spawning child processes
- Implement API key rotation and credential management for n8n integrations
- Monitor for CVE-2026-27577 (related expression evaluation flaw) and apply patches when available
CVEs associated with n8n Workflow Automation RCE via Expression Injection
Weaknesses (CWE) in n8n Workflow Automation RCE via Expression Injection
Timeline of n8n Workflow Automation RCE via Expression Injection
- CVE-2025-68613 published in NVD; n8n releases security patches v1.120.4, v1.121.1, v1.122.0 with expression sandbox hardening
- Censys identifies 103,476 potentially vulnerable n8n instances exposed to the internet; public PoC exploit code published on GitHub
- Spike in CVE-2025-68613 exploitation detected around Christmas period as attackers target holiday-period reduced staffing
- Resecurity publishes detailed technical analysis of CVE-2025-68613 including sandbox escape mechanism and exploit chain
- Akamai SIRT detects Zerobot botnet actively exploiting CVE-2025-68613 in global honeypot network; Mirai-variant zerobotv9 payloads observed
- Shadowserver Foundation reports 24,700+ unpatched n8n instances still exposed globally — 12,300+ in North America, 7,800+ in Europe
- Akamai SIRT publishes comprehensive analysis of Zerobot botnet campaign exploiting CVE-2025-68613 and CVE-2025-7544 with full IOCs
- CISA adds CVE-2025-68613 to Known Exploited Vulnerabilities catalog confirming active exploitation; FCEB agencies given March 25, 2026 deadline to patch per BOD 22-01
- Threadlinqs Intelligence documents threat with full MITRE mappings, IOCs, and Zerobot botnet correlation for platform publication
- As of 2026-05-29, CVE-2025-68613 (n8n expression-injection RCE, CVSS 9.9) remains actively exploited: it sits in CISA KEV (added Mar 11), is exploited by the operating Zerobot botnet (Akamai/Intel 471), with 24,700+ unpatched internet-exposed instances and public PoCs. Patches exist, but mass exploitation continues and follow-on n8n CVEs extend the same flaw class.
Sources cited for n8n Workflow Automation RCE via Expression Injection
- CISA KEV Addition — CVE-2025-68613
- NVD — CVE-2025-68613
- GitHub Security Advisory GHSA-v98v-ff95-f3cp
- CISA Flags Actively Exploited n8n RCE Bug — 24,700 Instances Exposed
- CVE-2025-68613: Critical n8n RCE & Server Compromise — Orca Security
- CVE-2025-68613: RCE via Expression Injection in n8n — Resecurity
- Akamai SIRT — Zerobot Malware Targets n8n Automation Platform
- Akamai SIRT Identifies Zerobot Botnet Exploiting n8n — ThreatIntelReport
- n8n CVE-2025-68613 RCE Exploitation: A Detailed Guide — SecureLayer7
- CVE-2025-68613: Critical RCE in n8n — SOCRadar
- PoC Exploit for CVE-2025-68613 — Expression Injection RCE in n8n
- Nuclei Detection Template for CVE-2025-68613
- CVE-2025-68613 Authenticated Expression-Injection RCE in n8n — Penligent
Detection coverage for TL-2026-0226
As of 2026-03-14, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0226 across Splunk SPL, Microsoft KQL and Sigma, covering 23 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.