CVE-2025-68668·Python vulnerability
n8n is an open source workflow automation platform. From version 1.0.0 to before 2.0.0, a sandbox bypass vulnerability exists in the Python Code Node that uses Pyodide. An authenticated user with permission to create or modify workflows can exploit this vulnerability to execute arbitrary commands on the host system running n8n, using the same privileges as the n8n process. This issue has been patched in version 2.0.0. Workarounds for this issue involve disabling the Code Node by setting the environment variable NODES_EXCLUDE: "[\"n8n-nodes-base.code\"]", disabling Python support in the Code node by setting the environment variable N8N_PYTHON_ENABLED=false, which was introduced in n8n version 1.104.0, and configuring n8n to use the task runner based Python sandbox via the N8N_RUNNERS_ENABLED and N8N_NATIVE_PYTHON_RUNNER environment variables.
- Severity
- critical
- Software
- Python
- Fixed in
- 2.0.0
- Published
- 2025-12-26
Affected versions
From: 1.0.0
Until: 2.0.0
Fixed in: 2.0.0
How to fix this CVE
Upgrade n8n to version 2.0.0 or later to patch the Python sandbox escape vulnerability in the Code Node. If immediate upgrade is not possible, disable Python execution by setting N8N_PYTHON_ENABLED=false (available in v1.104.0+) or exclude the Code Node entirely with NODES_EXCLUDE environment variable to prevent authenticated attackers from running arbitrary commands on your system.
sudo dnf update python3Defensia detects this vulnerability
How to check if you are affected
- Check n8n version: curl http://localhost:5678/api/v1/health 2>/dev/null | grep -i version or check package: npm list n8n | grep n8n
- Verify if Python Code Node is enabled: grep -E 'NODES_EXCLUDE|N8N_PYTHON_ENABLED' /path/to/.env or check active nodes in n8n UI under Settings > Community Nodes
- Search n8n audit logs for Code Node workflow executions: grep -i 'code.*node' /var/log/n8n/*.log or check database audit table for workflow_execute events with python or code node type
- Confirm remediation: Upgrade to n8n v2.0.0+ and verify with curl http://localhost:5678/api/v1/health 2>/dev/null | jq '.version' or npm list n8n
FAQ
What is CVE-2025-68668?
CVE-2025-68668 is a critical sandbox escape vulnerability in n8n's Python Code Node (using Pyodide) affecting versions 1.0.0 through 1.99.x. An authenticated user with workflow creation permissions can bypass sandbox restrictions and execute arbitrary shell commands with the privileges of the n8n process, potentially compromising the entire host system.
Is CVE-2025-68668 being actively exploited?
No, according to CISA KEV data, CVE-2025-68668 is not currently listed as actively exploited in the wild. However, the attack requires only authentication and workflow modification permissions, making it a significant risk for multi-user n8n deployments.
What versions of n8n are affected by CVE-2025-68668?
n8n versions 1.0.0 through 1.99.x are vulnerable. The vulnerability has been fixed in version 2.0.0 and later. Users on any version from 1.0.0 up to but not including 2.0.0 should take immediate action.
How do I check if my server is vulnerable to CVE-2025-68668?
Run: npm list n8n or docker exec <container> npm list n8n to check your installed version. If the version is between 1.0.0 and 1.99.x and Python Code Node is enabled (N8N_PYTHON_ENABLED not set to false), your system is vulnerable.
Does Defensia detect CVE-2025-68668?
Yes — Defensia's CVE advisory scanner compares installed n8n package versions against the NVD database and detects this vulnerability on any server running affected versions. If n8n is installed on a monitored server, CVE-2025-68668 will appear in your dashboard with direct remediation steps and workaround guidance.
Related Python CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2025-68668. Free for 1 server.
Get started free