Security Digest: October 30, 2025 - 2 Critical Vulnerabilities
Today's security alert highlights two high-severity vulnerabilities affecting n8n and Statamic CMS. Immediate patching is essential.
· 3 min read
Security Alert: Critical Vulnerabilities Discovered in n8n and Statamic CMS
Executive Summary
Today's security alert highlights two high-severity vulnerabilities affecting n8n and Statamic CMS. These vulnerabilities could allow remote code execution and unauthorized access to admin accounts. Immediate patching and configuration updates are essential to safeguard your systems.
Critical Vulnerabilities
CVE-2025-62726: Remote Code Execution in n8n Git Node
- Impact: Allows attackers to execute arbitrary code within the n8n environment, compromising systems and credentials.
- Affected Systems: All n8n Cloud and Self-Hosted versions using the Git Node feature.
- Immediate Action: Upgrade to v1.113.0 immediately. For self-hosted deployments, set the environment variable
N8N_GIT_NODE_DISABLE_BARE_REPOS=true. - Mitigation: Avoid using Git Node with untrusted repositories until the upgrade is complete.
CVE-2025-64112: Stored XSS in Statamic CMS Collections and Taxonomies
- Impact: Allows authenticated users to inject malicious JavaScript, potentially changing super admin credentials.
- Affected Systems: Versions up to and including 5.22.0 of Statamic CMS.
- Immediate Action: Upgrade to version 5.22.1 immediately. Ensure all users with content creation permissions are made aware of the vulnerability.
- Mitigation: Limit content creation permissions to trusted users only.
What to Do Now
- Prioritize upgrading n8n and Statamic CMS to the latest secure versions.
- Verify environment configurations to disable risky features.
- Implement monitoring for any unauthorized changes or suspicious activities post-upgrade.