Junglewise Threat Intelligence

n8n Google Service Account private key exposure in JWT header

Severity: medium · CVSS 4 · Published 2026-07-22

Technologies: N8n. Vendors: N8n.

Executive brief

n8n is a workflow automation platform. When configured with Google Service Account credentials, the platform mistakenly placed the full private cryptographic key in the JWT header as a key identifier, where it could be read by anyone logging or inspecting network traffic. An attacker with access to JWT data could impersonate the service account and gain full access to any Google Cloud resources the account was authorized to use.

Technical details

The vulnerability is a credential exposure flaw (CWE-312) affecting n8n's Google Service Account integration. The root cause was improper use of the JWT header's "kid" (key ID) field—intended only for a short identifier—to store the entire PEM-encoded private key. Since JWT headers are only Base64-encoded (not encrypted), the key could be trivially recovered by inspecting JWTs in transit, logs, or proxy records. An attacker with network visibility or log access could extract the key and authenticate to Google Cloud APIs as the service account. The vulnerability required the victim to be using Google Service Account credentials. Patches were released in versions 1.123.64, 2.29.8, and 2.30.1.

Affected products

  • n8n n8n < 1.123.64, < 2.29.8, < 2.30.1

Timeline

  • 2026-07-08: disclosed
  • 2026-07-22: advisory
  • 2026-07-22: patched: Versions 1.123.64, 2.29.8, and 2.30.1 released

References

Related threats