{"data":{"id":"58d2d20c-20e8-405a-a99a-7d10ec32f2e2","title":"GHSA-9r8p-h6cc-6qhm: n8n: Google Service Account Private Key Exposed in JWT Header","summary":"n8n, a workflow automation tool, accidentally exposed Google Service Account private keys in JWT headers (the unencrypted metadata attached to authentication tokens). Because JWT headers were only Base64-encoded (a simple encoding, not encryption), attackers could extract these keys and impersonate the service account to access Google Cloud resources. Only instances using Google Service Account credentials were affected.","solution":"The issue has been fixed in n8n versions 1.123.64, 2.29.8, and 2.30.1. Users should upgrade to one of these versions or later. If upgrading is not immediately possible, administrators should avoid using Google Service Account credentials until patched, rotate any exposed Google Service Account keys, and review proxy, load balancer, and application logs for JWT headers containing exposed key material.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-9r8p-h6cc-6qhm","publishedAt":"2026-07-22T18:00:09.000Z","cveId":"CVE-2026-65599","cweIds":null,"cvssScore":null,"cvssSeverity":"medium","severity":"medium","attackType":["supply_chain"],"issueType":"vulnerability","affectedPackages":["n8n@>= 2.0.0-rc.0, < 2.29.8 (fixed: 2.29.8)","n8n@>= 2.30.0, < 2.30.1 (fixed: 2.30.1)","n8n@< 1.123.64 (fixed: 1.123.64)"],"affectedVendors":[],"affectedVendorsRaw":["n8n"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0,"patchAvailable":true,"disclosureDate":"2026-07-22T18:00:09.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality","integrity"],"aiComponentTargeted":"api","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":["AML.T0010"]}}