Detects n8n instances where form webhook endpoints accept Content-Type: application/json, bypassing the multipart file upload parser. An unauthenticated attacker can control the files.filepath field to read any file on the server, including /etc/passwd, n8n encryption keys, and the database. Combined with CVE-2025-68613, this enables full RCE.
Is your app exploitable through CVE-2026-21858?
Scan your domain free