The 485 products listed only once: the tiers of repetition side by side
Remote code execution through expression evaluation in the workflow automation tool n8n. The product appears once, and such products account for 485 of 711.
Key facts
- CVE IDCVE-2025-68613
- Affected (vendor / product)n8n n8n
- CWECWE-913
- ExploitationListed in CISA KEV (exploitation confirmed)
- Remediation due2026-03-25 (U.S. federal civilian agencies, BOD 22-01)
Key points
- Remote code execution in n8n from improper control of dynamically managed code resources in workflow expression evaluation.
- Added 11 March 2026 with a 25 March deadline, a fourteen-day window, referenced by a GitHub security advisory.
- Of the 1,695 KEV records this site holds as of 2026-09-06, across 711 products, 485 (68.2%) appear once.
- Meanwhile the 19 products listed ten or more times (2.7%) account for 562 records (33.2%).
1Most of the products are ones you have never heard of
The previous article covered a second appearance. This product appears once — and that tier is the largest by product count.
| Appearances | Products | Records in that tier |
|---|---|---|
| 10 or more | 19 products | 562 |
| 5 to 9 | 34 products | 209 |
| 3 to 4 | 66 products | 225 |
| Exactly 2 | 107 products | 214 |
| Exactly 1 | 485 products | 485 |
| Total | 711 products | 1,695 |
By product, 68.2% (485) appear once. Counted by record the picture inverts: the 19 products listed ten or more times — 2.7% of products — account for 562 records, 33.2% of the catalog.
Concentrated in a few products and mostly one-time products are both true at once.
2What this record shows
The flaw lies in evaluating workflow expressions, where control of dynamically managed code resources was insufficient (CWE-913). The design itself — executing expressions a user writes — is the attack surface. The reference is a GitHub security advisory rather than a vendor product page: the place of development is also the place of disclosure.
3What the eight records showed
- 1172 times (Windows)A broad product keeps yielding varied defects
- 253 times (Apple)The product field groups several systems; reach appears only in the description
- 340 times (Chromium V8)Records filed by component name are invisible to a search by browser name
- 433 times (Flash Player)The action becomes discontinue rather than update
- 528 times (Linux kernel)A shared component has no single party to fix it
- 617 times (Zimbra)One product repeats one weakness type, sometimes with a three-day window
- 72 times (Cisco FMC)A low count still tops the queue when the conditions align
- 81 time (n8n)68.2% of products belong to this tier
Why it matters
Records concentrate in a few products while most products appear once. Monitoring has to combine continuous attention to the repeat offenders with a way of catching one-time entries that name-based tracking will miss.
FAQ
Why do so many products appear only once?
Why is expression evaluation risky?
How should monitoring scope be decided?
Sources (primary)
This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.
- CISA KEV Catalog (known exploited list)
- NVD (CVE details / CVSS)
- Vendor / reference advisory
- This product uses data from the NVD API but is not endorsed or certified by the NVD. KEV data is CC0 (public domain).