N8n: Duplicate Advisory: Google Service Account Private Key Exposed in JWT Header
n8n versions before 1.123.64, 2.29.8, and 2.30.1 have a vulnerability where the full Google Service Account private key is exposed in the JWT header's kid field. This exposure occurs because the private key was mistakenly placed in a Base64-encoded JWT header, which is not encrypted. An attacker with access to the JWT could recover the private key and impersonate the service account, potentially accessing or modifying authorized Google Cloud resources. Only instances configured with Google Service Account credentials are affected. This advisory is a duplicate and has been withdrawn in favor of GHSA-9r8p-h6cc-6qhm.
AI Analysis
Technical Summary
The vulnerability in n8n prior to versions 1.123.64, 2.29.8, and 2.30.1 involves the accidental inclusion of the full PEM private key of a Google Service Account in the JWT header's kid field. Since JWT headers are Base64-encoded and not encrypted, anyone with access to the JWT can decode and recover the private key. This exposure allows an attacker to impersonate the Google Service Account, potentially gaining unauthorized access to or control over Google Cloud resources authorized to that account. The issue affects only n8n instances configured with Google Service Account credentials. The advisory is a duplicate and has been withdrawn, referencing GHSA-9r8p-h6cc-6qhm for the original details.
Potential Impact
Exposure of the Google Service Account private key enables attackers to impersonate the service account, potentially accessing or modifying any Google Cloud resources authorized to that account. This can lead to unauthorized data access, resource manipulation, or other malicious actions within the affected cloud environment. The vulnerability only impacts n8n instances configured with Google Service Account credentials.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory GHSA-9r8p-h6cc-6qhm for current remediation guidance. Until a fix is applied, avoid using Google Service Account credentials with affected n8n versions or restrict access to JWT tokens to prevent key exposure. Monitor official n8n channels for updates and apply patches once available.
N8n: Duplicate Advisory: Google Service Account Private Key Exposed in JWT Header
Description
n8n versions before 1.123.64, 2.29.8, and 2.30.1 have a vulnerability where the full Google Service Account private key is exposed in the JWT header's kid field. This exposure occurs because the private key was mistakenly placed in a Base64-encoded JWT header, which is not encrypted. An attacker with access to the JWT could recover the private key and impersonate the service account, potentially accessing or modifying authorized Google Cloud resources. Only instances configured with Google Service Account credentials are affected. This advisory is a duplicate and has been withdrawn in favor of GHSA-9r8p-h6cc-6qhm.
CVSS v4.0
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in n8n prior to versions 1.123.64, 2.29.8, and 2.30.1 involves the accidental inclusion of the full PEM private key of a Google Service Account in the JWT header's kid field. Since JWT headers are Base64-encoded and not encrypted, anyone with access to the JWT can decode and recover the private key. This exposure allows an attacker to impersonate the Google Service Account, potentially gaining unauthorized access to or control over Google Cloud resources authorized to that account. The issue affects only n8n instances configured with Google Service Account credentials. The advisory is a duplicate and has been withdrawn, referencing GHSA-9r8p-h6cc-6qhm for the original details.
Potential Impact
Exposure of the Google Service Account private key enables attackers to impersonate the service account, potentially accessing or modifying any Google Cloud resources authorized to that account. This can lead to unauthorized data access, resource manipulation, or other malicious actions within the affected cloud environment. The vulnerability only impacts n8n instances configured with Google Service Account credentials.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory GHSA-9r8p-h6cc-6qhm for current remediation guidance. Until a fix is applied, avoid using Google Service Account credentials with affected n8n versions or restrict access to JWT tokens to prevent key exposure. Monitor official n8n channels for updates and apply patches once available.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-mhvh-gwhr-76pw
- Osv Schema Version
- 1.4.0
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 4.0
Threat ID: 6a6151339c2644c7f8da74ee
Added to database: 07/22/2026, 23:24:35 UTC
Last enriched: 07/23/2026, 00:10:11 UTC
Last updated: 09/03/2026, 12:25:05 UTC
Views: 60
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.