InfoSec News Nuggets 12/23/2025

Critical n8n RCE vulnerability enables full server compromise A critical remote code execution flaw in the n8n workflow automation platform, tracked as CVE-2025-68613 (CVSS 9.9), allows authenticated users to inject expressions that escape the workflow sandbox and execute arbitrary OS commands on the host server. The issue affects versions from 0.211.0 up to but not including 1.120.4, 1.121.1, and 1.122.0, enabling full instance takeover, data exposure, and lateral movement if unpatched.   Threat Actors Exploit…
Read More