GHSA-mhvh-gwhr-76pw: Duplicate Advisory: Google Service Account Private Key Exposed in JWT Header
Summary
n8n versions before 1.123.64, 2.29.8, and 2.30.1 had a credential exposure vulnerability where Google Service Account private keys (secret authentication material) were incorrectly placed in JWT headers (the unencrypted part of a token that carries metadata) instead of being kept secure. Since JWT headers are only Base64-encoded (a reversible encoding format, not encryption), attackers could extract the private key and impersonate the service account to access Google Cloud resources.
Solution / Mitigation
Update n8n to version 1.123.64, 2.29.8, or 2.30.1 or later. Only instances using Google Service Account credentials are affected.
Classification
Affected Vendors
Affected Packages
Related Issues
Original source: https://github.com/advisories/GHSA-mhvh-gwhr-76pw
First tracked: July 22, 2026 at 02:00 PM
Classified by LLM (prompt v3) · confidence: 85%