N8n < 2.0.0 Multiple Vulnerabilities

critical Web App Scanning Plugin ID 115103

Synopsis

N8n < 2.0.0 Multiple Vulnerabilities

Description

According to its banner, the version of n8n running on the remote host is 1.0.0 or later and before 2.0.0. It is, therefore, affected by multiple vulnerabilities:

- An authenticated arbitrary file read and file write vulnerability

- An authenticated arbitrary command execution vulnerability in Pyodide based Python code node

Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade to n8n version 2.0.0 or later.

See Also

https://docs.n8n.io/release-notes/

https://github.com/n8n-io/n8n/security/advisories/GHSA-62r4-hw23-cc8v

https://github.com/n8n-io/n8n/security/advisories/GHSA-j4p8-h8mh-rh8q

Plugin Details

Severity: Critical

ID: 115103

Type: remote

Published: 1/8/2026

Updated: 1/8/2026

Scan Template: api, basic, full, pci, scan

Risk Information

VPR

Risk Factor: Critical

Score: 9.9

CVSS v2

Risk Factor: High

Base Score: 9

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2025-68668

CVSS v3

Risk Factor: Critical

Base Score: 9.9

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CVSS Score Source: CVE-2025-68668

Vulnerability Information

CPE: cpe:2.3:a:n8n:n8n:*:*:*:*:*:*:*:*

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 12/25/2025

Reference Information

CVE: CVE-2025-68668, CVE-2025-68697