# n8n Workflow Automation RCE via Expression Injection — CVE-2025-68613 (CVSS 9.9) Active Exploitation by Zerobot Botnet

> Critical RCE vulnerability (CVSS 9.9) in n8n workflow automation platform versions 0.211.0 through 1.120.3 and 1.121.0, actively exploited in the wild by the Zerobot botnet to deploy Mirai-variant malware. Insufficient sandbox isolation in the expression evaluation engine allows authenticated attackers to escape the JavaScript sandbox via Node.js this context and execute arbitrary OS commands. CISA added CVE-2025-68613 to the KEV catalog on March 11, 2026 with a federal patch deadline of March 25, 2026. Over 24,700 unpatched instances remain exposed globally.

- **Published:** 2026-03-14T12:00:00Z
- **Last reviewed:** 2026-03-14T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0226
- **ID:** TL-2026-0226
- **Severity:** CRITICAL (CVSS 9.9)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Actor:** Zerobot Botnet
- **Detections:** 9 · **IOCs:** 23 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2025-68613

## Description

CVE-2025-68613 is a critical Remote Code Execution vulnerability in n8n, a popular open-source workflow automation platform used by thousands of organizations for business process automation, data integration, and AI workflow orchestration.

The vulnerability resides in n8n's server-side expression evaluation engine, which processes JavaScript expressions wrapped in {{ }} delimiters within workflow node parameters. The core flaw is that the execution sandbox fails to properly isolate the evaluation context from the Node.js runtime. Specifically, the JavaScript this keyword within evaluated expressions exposes the Node.js global context, granting access to the process object. An attacker can leverage this to call process.mainModule.require('child_process').execSync() to execute arbitrary OS-level commands with the privileges of the n8n process.

The exploit chain is straightforward:
1. An authenticated user (no elevated privileges required) creates or modifies a workflow via the REST API (POST /rest/workflows)
2. A malicious expression is injected into a node parameter (typically using the n8n-nodes-base.set node type)
3. When the workflow is activated or executed, the expression evaluator processes the payload
4. The JavaScript escapes the sandbox via this.process.mainModule.require()
5. The child_process module is loaded and execSync() executes arbitrary commands

The canonical exploit payload is: {{ (function(){ return this.process.mainModule.require('child_process').execSync('COMMAND').toString() })() }}

Akamai's Security Intelligence and Response Team (SIRT) identified active exploitation by the Zerobot botnet beginning in mid-January 2026, with campaign activity traced back to December 2025. The botnet exploits CVE-2025-68613 to deploy a Mirai-based malware variant called zerobotv9, which supports multiple architectures (x86, MIPS, ARM, PPC). The initial infection vector uses a shell script (tol.sh) downloaded from 144.172.100.228 that fetches and executes architecture-specific zerobotv9 binaries. The C2 infrastructure operates via 0bot.qzz[.]io.

Shadowserver Foundation data from February 2026 shows 24,700+ unpatched n8n instances exposed globally, with 12,300+ in North America and 7,800+ in Europe. Censys reported 103,476 potentially vulnerable instances as of December 22, 2025. The EPSS score is 76.93% (99th percentile), indicating extremely high probability of exploitation.

The vulnerability was patched in December 2025 with versions 1.120.4, 1.121.1, and 1.122.0, which introduce additional safeguards to restrict expression evaluation and prevent sandbox escapes. A related vulnerability, CVE-2026-27577 (CVSS 9.4), was subsequently discovered by Pillar Security in the same expression evaluation system.

Organizations running self-hosted n8n instances must patch immediately or implement strict access controls to limit workflow creation and editing to trusted users only.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1059 Command and Scripting Interpreter
- T1203 Exploitation for Client Execution
- T1505 Server Software Component
- T1053 Scheduled Task/Job
- T1068 Exploitation for Privilege Escalation
- T1027 Obfuscated Files or Information
- T1140 Deobfuscate/Decode Files or Information
- T1070 Indicator Removal
- T1552 Unsecured Credentials
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1087 Account Discovery
- T1005 Data from Local System
- T1071 Application Layer Protocol
- T1571 Non-Standard Port
- T1105 Ingress Tool Transfer
- T1041 Exfiltration Over C2 Channel
- T1496 Resource Hijacking

## Sources

- [CISA KEV Addition — CVE-2025-68613](https://www.cisa.gov/news-events/alerts/2026/03/11/cisa-adds-one-known-exploited-vulnerability-catalog)
- [NVD — CVE-2025-68613](https://nvd.nist.gov/vuln/detail/CVE-2025-68613)
- [GitHub Security Advisory GHSA-v98v-ff95-f3cp](https://github.com/n8n-io/n8n/security/advisories/GHSA-v98v-ff95-f3cp)
- [CISA Flags Actively Exploited n8n RCE Bug — 24,700 Instances Exposed](https://thehackernews.com/2026/03/cisa-flags-actively-exploited-n8n-rce.html)
- [CVE-2025-68613: Critical n8n RCE & Server Compromise — Orca Security](https://orca.security/resources/blog/cve-2025-68613-n8n-rce-vulnerability/)
- [CVE-2025-68613: RCE via Expression Injection in n8n — Resecurity](https://www.resecurity.com/blog/article/cve-2025-68613-remote-code-execution-via-expression-injection-in-n8n-2)
- [Akamai SIRT — Zerobot Malware Targets n8n Automation Platform](https://www.akamai.com/blog/security-research/zerobot-malware-targets-n8n-automation-platform)
- [Akamai SIRT Identifies Zerobot Botnet Exploiting n8n — ThreatIntelReport](https://www.threatintelreport.com/2026/02/28/vulnerabilities_exploits/akamai-sirt-identifies-zerobot-botnet-exploiting-n8n-and-tenda-vulnerabilities/)
- [n8n CVE-2025-68613 RCE Exploitation: A Detailed Guide — SecureLayer7](https://blog.securelayer7.net/cve-2025-68613-n8n-rce-exploitation/)
- [CVE-2025-68613: Critical RCE in n8n — SOCRadar](https://socradar.io/blog/cve-2025-68613-rce-n8n-workflow-automation/)
- [PoC Exploit for CVE-2025-68613 — Expression Injection RCE in n8n](https://github.com/mbanyamer/n8n-Authenticated-Expression-Injection-RCE-CVE-2025-68613)
- [Nuclei Detection Template for CVE-2025-68613](https://github.com/Ashwesker/Blackash-CVE-2025-68613/blob/main/CVE-2025-68613.yaml)
- [CVE-2025-68613 Authenticated Expression-Injection RCE in n8n — Penligent](https://www.penligent.ai/hackinglabs/cve-2025-68613-authenticated-expression-injection-rce-in-n8n-cwe-913-whats-affected-what-to-patch-and-how-to-contain-it/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0226
