All verified exploits

CVE-2026-21877 Git Node Arbitrary File Write RCE

Deterministic critical n8n Added cve-verified-cve-2026-21877

Detects n8n instances where the Git node does not validate the repositoryPath parameter against the isFilePathBlocked function. An authenticated user can specify a repository path pointing to sensitive directories, writing arbitrary files to the server and achieving remote code execution. Affects versions >= 0.123.0, < 1.121.3.

Is your app exploitable through CVE-2026-21877?

Scan your domain free