Detects n8n instances where the Git node does not validate the repositoryPath parameter against the isFilePathBlocked function. An authenticated user can specify a repository path pointing to sensitive directories, writing arbitrary files to the server and achieving remote code execution. Affects versions >= 0.123.0, < 1.121.3.
Is your app exploitable through CVE-2026-21877?
Scan your domain free