Junglewise Threat Intelligence

n8n Google Service Account private key exposure in JWT header

Severity: medium · CVSS 5.1 · Published 2026-07-22

Technologies: N8n. Vendors: N8n.

Executive brief

n8n is a workflow automation tool used to connect different software services. A security flaw was found where the private security keys for Google Service Accounts were accidentally included in plain text within data headers. This could allow anyone with access to system logs or network traffic to steal these keys and gain unauthorized access to your Google Cloud resources and data.

Technical details

A credential exposure vulnerability exists in n8n when configured with Google Service Account credentials. The application incorrectly places the full PEM private key into the JWT header's 'kid' (key identifier) field instead of a unique ID. Since JWT headers are only Base64-encoded and not encrypted, the private key is visible to any entity capable of intercepting the token or viewing application logs. An attacker with access to these tokens can extract the key to impersonate the service account and access authorized Google Cloud resources. The issue is addressed in versions 1.123.64, 2.29.8, and 2.30.1.

Affected products

  • n8n n8n < 1.123.64, < 2.29.8, < 2.30.1

Timeline

  • 2026-07-22: advisory: Advisory published to GitHub Database
  • 2026-07-22: other: Advisory withdrawn as a duplicate of GHSA-9r8p-h6cc-6qhm

References

Related threats