{"data":{"id":"7f3e69d7-faef-437e-b3ed-14a0c4716621","title":"GHSA-mhvh-gwhr-76pw: Duplicate Advisory: Google Service Account Private Key Exposed in JWT Header","summary":"n8n versions before 1.123.64, 2.29.8, and 2.30.1 had a credential exposure vulnerability where Google Service Account private keys (secret authentication material) were incorrectly placed in JWT headers (the unencrypted part of a token that carries metadata) instead of being kept secure. Since JWT headers are only Base64-encoded (a reversible encoding format, not encryption), attackers could extract the private key and impersonate the service account to access Google Cloud resources.","solution":"Update n8n to version 1.123.64, 2.29.8, or 2.30.1 or later. Only instances using Google Service Account credentials are affected.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-mhvh-gwhr-76pw","publishedAt":"2026-07-22T12:32:18.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":"medium","severity":"medium","attackType":["data_extraction"],"issueType":"vulnerability","affectedPackages":["n8n@< 1.123.64"],"affectedVendors":[],"affectedVendorsRaw":["n8n","Google"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"patchAvailable":null,"disclosureDate":"2026-07-22T12:32:18.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality","integrity"],"aiComponentTargeted":"api","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null}}