Two critical vulnerabilities were recently disclosed in n8n, the popular workflow automation tool, which could allow attackers to take full control of instances or steal sensitive data. Both flaws affect versions prior to 1.76.1.
The Vulnerabilities
- CVE-2025-24376 (RCE via Formula Injection): This is a Critical flaw (CVSS 9.9) that allows remote code execution. An attacker with “workflow edit” permissions can craft a malicious expression within a node—specifically using the
set or code nodes—to execute arbitrary commands on the host server. NVD Details
- CVE-2025-24375 (Credential Exposure): This vulnerability allows an attacker to bypass security controls and access decrypted credentials stored within the n8n database. This is particularly dangerous because n8n often holds API keys and passwords for high-value services like AWS, Google, and Slack. GitHub Security Advisory
Affected Versions
- All versions of n8n older than 1.76.1 are considered vulnerable.
- Self-hosted instances are at the highest risk, especially those exposed to the public internet without strict IP whitelisting.
Required Action
- Update Immediately: Update your n8n instance to version 1.76.1 or later. The fix involves improved sanitization of expressions and tighter access controls on the credential storage API. n8n Release Notes
- Audit Permissions: Ensure that only trusted users have “Edit” permissions for workflows, as the RCE exploit requires the ability to modify node configurations.
- Rotate Credentials: As a precaution, if your instance was publicly accessible and unpatched, consider rotating high-stakes API keys and passwords stored in the “Credentials” section.