Exploited Known exploited (KEV) CVE-2025-68613

The 485 products listed only once: the tiers of repetition side by side

n8n n8n Added to KEV Mar 11, 2026 Federal remediation due 2026-03-25

Remote code execution through expression evaluation in the workflow automation tool n8n. The product appears once, and such products account for 485 of 711.

Key facts

  • CVE IDCVE-2025-68613
  • Affected (vendor / product)n8n n8n
  • CWECWE-913
  • ExploitationListed in CISA KEV (exploitation confirmed)
  • Remediation due2026-03-25 (U.S. federal civilian agencies, BOD 22-01)

Key points

  • Remote code execution in n8n from improper control of dynamically managed code resources in workflow expression evaluation.
  • Added 11 March 2026 with a 25 March deadline, a fourteen-day window, referenced by a GitHub security advisory.
  • Of the 1,695 KEV records this site holds as of 2026-09-06, across 711 products, 485 (68.2%) appear once.
  • Meanwhile the 19 products listed ten or more times (2.7%) account for 562 records (33.2%).

1Most of the products are ones you have never heard of

The previous article covered a second appearance. This product appears once — and that tier is the largest by product count.

AppearancesProductsRecords in that tier
10 or more19 products562
5 to 934 products209
3 to 466 products225
Exactly 2107 products214
Exactly 1485 products485
Total711 products1,695

By product, 68.2% (485) appear once. Counted by record the picture inverts: the 19 products listed ten or more times — 2.7% of products — account for 562 records, 33.2% of the catalog.

Share of products appearing once485 / 711
Share of products appearing ten or more times19 / 711
Share of records from products appearing once485 / 1695
Share of records from products appearing ten or more times562 / 1695

Concentrated in a few products and mostly one-time products are both true at once.

2What this record shows

The flaw lies in evaluating workflow expressions, where control of dynamically managed code resources was insufficient (CWE-913). The design itself — executing expressions a user writes — is the attack surface. The reference is a GitHub security advisory rather than a vendor product page: the place of development is also the place of disclosure.

3What the eight records showed

  1. 1172 times (Windows)A broad product keeps yielding varied defects
  2. 253 times (Apple)The product field groups several systems; reach appears only in the description
  3. 340 times (Chromium V8)Records filed by component name are invisible to a search by browser name
  4. 433 times (Flash Player)The action becomes discontinue rather than update
  5. 528 times (Linux kernel)A shared component has no single party to fix it
  6. 617 times (Zimbra)One product repeats one weakness type, sometimes with a three-day window
  7. 72 times (Cisco FMC)A low count still tops the queue when the conditions align
  8. 81 time (n8n)68.2% of products belong to this tier

Why it matters

Records concentrate in a few products while most products appear once. Monitoring has to combine continuous attention to the repeat offenders with a way of catching one-time entries that name-based tracking will miss.

FAQ

Why do so many products appear only once?
The records do not explain it. The fact is that 485 of 711 products appear a single time.
Why is expression evaluation risky?
Because the design executes expressions written by a user. Without sufficient control, arbitrary code can be introduced in the form of an expression.
How should monitoring scope be decided?
Watch the small set of repeat products continuously, and pair that with tracking that does not depend on product names, since most products appear only once.

Sources (primary)

This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.

#KEV#Known exploited#n8n#Code execution#Vulnerability management
Disclaimer: This site independently summarizes and classifies information based on official data sources. Always verify the latest and accurate information with the official sources. Content on finance, health, legal, and security is information, not advice. This site is not an official website of the U.S. government.