google-cloud-aiplatform
Vertex AI API client library
Activity
- Latest release
- 1w ago
- Total releases
- 220
- Cadence
- ~6 days
- Last 12 months
- 54
Details
- License
- Apache-2.0
- First release
- Nov 09, 2020
| Version | Released | |
|---|---|---|
2.1.0
minor
| ||
2.0.1
patch
| ||
1.165.1
patch
| ||
1.165.0
minor
| ||
1.164.0
minor
| ||
1.163.0
minor
| ||
1.162.0
minor
| ||
1.161.0
minor
| ||
1.160.0
minor
| ||
1.159.0
minor
| ||
2.0.0
major
| ||
1.158.0
minor
| ||
1.157.0
minor
| ||
1.156.0
minor
| ||
1.155.0
minor
| ||
1.154.0
minor
| ||
1.153.1
patch
| ||
1.153.0
minor
| ||
1.152.0
minor
| ||
1.151.0
minor
| ||
1.150.0
minor
| ||
1.149.0
minor
| ||
1.148.1
patch
| ||
1.148.0
minor
| ||
1.147.0
minor
| ||
1.146.0
minor
| ||
1.145.0
minor
| ||
1.144.0
minor
| ||
1.143.0
minor
| ||
1.142.0
minor
| ||
1.141.0
minor
| ||
1.140.0
minor
| ||
1.139.0
minor
| ||
1.138.0
minor
| ||
1.137.0
minor
| ||
1.136.0
minor
| ||
1.135.0
minor
| ||
1.134.0
minor
| ||
1.133.0
minor
| ||
1.132.0
minor
1 CVE
CVE-2026-2473
PYSEC-2026-2500
GHSA-wh2j-26j7-9728
Jul 13, 2026
Google Cloud Vertex AI has a a vulnerability involving predictable bucket naming
Critical
Network
Low
None
Predictable bucket naming in Vertex AI Experiments in Google Cloud Vertex AI from version 1.21.0 up to (but not including) 1.133.0 on Google Cloud Platform allows an unauthenticated remote attacker to achieve cross-tenant remote code execution, model theft, and poisoning via pre-creating predictably named Cloud Storage buckets (Bucket Squatting). This vulnerability was patched and no customer action is needed. Affected versions
1.100.0
1.101.0
1.102.0
1.103.0
1.104.0
1.105.0
1.106.0
1.107.0
1.108.0
1.109.0
1.110.0
1.111.0
+ 120 more Show less
1.112.0
1.113.0
1.114.0
1.115.0
1.116.0
1.117.0
1.118.0
1.119.0
1.120.0
1.121.0
1.122.0
1.123.0
1.124.0
1.125.0
1.126.0
1.126.1
1.127.0
1.128.0
1.129.0
1.130.0
1.131.0
1.132.0
1.21.0
1.22.0
1.22.1
1.23.0
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.28.0
1.28.1
1.29.0
1.30.0
1.30.1
1.31.0
1.31.1
1.32.0
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.36.1
1.36.2
1.36.3
1.36.4
1.37.0
1.38.0
1.38.1
1.39.0
1.40.0
1.41.0
1.42.0
1.42.1
1.43.0
1.44.0
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.50.0
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.0
1.59.0
1.60.0
1.61.0
1.62.0
1.63.0
1.64.0
1.65.0
1.66.0
1.67.0
1.67.1
1.68.0
1.69.0
1.70.0
1.71.0
1.71.1
1.72.0
1.73.0
1.74.0
1.75.0
1.76.0
1.77.0
1.78.0
1.79.0
1.80.0
1.81.0
1.82.0
1.83.0
1.84.0
1.85.0
1.86.0
1.87.0
1.88.0
1.89.0
1.90.0
1.91.0
1.92.0
1.93.0
1.93.1
1.94.0
1.95.0
1.95.1
1.96.0
1.97.0
1.98.0
1.99.0
Fixed in
1.133.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.131.0
minor
1 CVE
CVE-2026-2473
PYSEC-2026-2500
GHSA-wh2j-26j7-9728
Jul 13, 2026
Google Cloud Vertex AI has a a vulnerability involving predictable bucket naming
Critical
Network
Low
None
Predictable bucket naming in Vertex AI Experiments in Google Cloud Vertex AI from version 1.21.0 up to (but not including) 1.133.0 on Google Cloud Platform allows an unauthenticated remote attacker to achieve cross-tenant remote code execution, model theft, and poisoning via pre-creating predictably named Cloud Storage buckets (Bucket Squatting). This vulnerability was patched and no customer action is needed. Affected versions
1.100.0
1.101.0
1.102.0
1.103.0
1.104.0
1.105.0
1.106.0
1.107.0
1.108.0
1.109.0
1.110.0
1.111.0
+ 120 more Show less
1.112.0
1.113.0
1.114.0
1.115.0
1.116.0
1.117.0
1.118.0
1.119.0
1.120.0
1.121.0
1.122.0
1.123.0
1.124.0
1.125.0
1.126.0
1.126.1
1.127.0
1.128.0
1.129.0
1.130.0
1.131.0
1.132.0
1.21.0
1.22.0
1.22.1
1.23.0
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.28.0
1.28.1
1.29.0
1.30.0
1.30.1
1.31.0
1.31.1
1.32.0
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.36.1
1.36.2
1.36.3
1.36.4
1.37.0
1.38.0
1.38.1
1.39.0
1.40.0
1.41.0
1.42.0
1.42.1
1.43.0
1.44.0
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.50.0
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.0
1.59.0
1.60.0
1.61.0
1.62.0
1.63.0
1.64.0
1.65.0
1.66.0
1.67.0
1.67.1
1.68.0
1.69.0
1.70.0
1.71.0
1.71.1
1.72.0
1.73.0
1.74.0
1.75.0
1.76.0
1.77.0
1.78.0
1.79.0
1.80.0
1.81.0
1.82.0
1.83.0
1.84.0
1.85.0
1.86.0
1.87.0
1.88.0
1.89.0
1.90.0
1.91.0
1.92.0
1.93.0
1.93.1
1.94.0
1.95.0
1.95.1
1.96.0
1.97.0
1.98.0
1.99.0
Fixed in
1.133.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.130.0
minor
2 CVEs
CVE-2026-2473
PYSEC-2026-2500
GHSA-wh2j-26j7-9728
Jul 13, 2026
Google Cloud Vertex AI has a a vulnerability involving predictable bucket naming
Critical
Network
Low
None
Predictable bucket naming in Vertex AI Experiments in Google Cloud Vertex AI from version 1.21.0 up to (but not including) 1.133.0 on Google Cloud Platform allows an unauthenticated remote attacker to achieve cross-tenant remote code execution, model theft, and poisoning via pre-creating predictably named Cloud Storage buckets (Bucket Squatting). This vulnerability was patched and no customer action is needed. Affected versions
1.100.0
1.101.0
1.102.0
1.103.0
1.104.0
1.105.0
1.106.0
1.107.0
1.108.0
1.109.0
1.110.0
1.111.0
+ 120 more Show less
1.112.0
1.113.0
1.114.0
1.115.0
1.116.0
1.117.0
1.118.0
1.119.0
1.120.0
1.121.0
1.122.0
1.123.0
1.124.0
1.125.0
1.126.0
1.126.1
1.127.0
1.128.0
1.129.0
1.130.0
1.131.0
1.132.0
1.21.0
1.22.0
1.22.1
1.23.0
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.28.0
1.28.1
1.29.0
1.30.0
1.30.1
1.31.0
1.31.1
1.32.0
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.36.1
1.36.2
1.36.3
1.36.4
1.37.0
1.38.0
1.38.1
1.39.0
1.40.0
1.41.0
1.42.0
1.42.1
1.43.0
1.44.0
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.50.0
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.0
1.59.0
1.60.0
1.61.0
1.62.0
1.63.0
1.64.0
1.65.0
1.66.0
1.67.0
1.67.1
1.68.0
1.69.0
1.70.0
1.71.0
1.71.1
1.72.0
1.73.0
1.74.0
1.75.0
1.76.0
1.77.0
1.78.0
1.79.0
1.80.0
1.81.0
1.82.0
1.83.0
1.84.0
1.85.0
1.86.0
1.87.0
1.88.0
1.89.0
1.90.0
1.91.0
1.92.0
1.93.0
1.93.1
1.94.0
1.95.0
1.95.1
1.96.0
1.97.0
1.98.0
1.99.0
Fixed in
1.133.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-2472
PYSEC-2026-2499
GHSA-qv8j-hgpc-vrq8
Jul 13, 2026
Google Cloud Vertex AI SDK affected by Stored Cross-Site Scripting (XSS)
Critical
Network
Low
Low
Stored Cross-Site Scripting (XSS) in the _genai/_evals_visualization component of Google Cloud Vertex AI SDK (google-cloud-aiplatform) versions from 1.98.0 up to (but not including) 1.131.0 allows an unauthenticated remote attacker to execute arbitrary JavaScript in a victim's Jupyter or Colab environment via injecting script escape sequences into model evaluation results or dataset JSON data. Affected versions
1.100.0
1.101.0
1.102.0
1.103.0
1.104.0
1.105.0
1.106.0
1.107.0
1.108.0
1.109.0
1.110.0
1.111.0
+ 22 more Show less
1.112.0
1.113.0
1.114.0
1.115.0
1.116.0
1.117.0
1.118.0
1.119.0
1.120.0
1.121.0
1.122.0
1.123.0
1.124.0
1.125.0
1.126.0
1.126.1
1.127.0
1.128.0
1.129.0
1.130.0
1.98.0
1.99.0
Fixed in
1.131.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.129.0
minor
2 CVEs
CVE-2026-2473
PYSEC-2026-2500
GHSA-wh2j-26j7-9728
Jul 13, 2026
Google Cloud Vertex AI has a a vulnerability involving predictable bucket naming
Critical
Network
Low
None
Predictable bucket naming in Vertex AI Experiments in Google Cloud Vertex AI from version 1.21.0 up to (but not including) 1.133.0 on Google Cloud Platform allows an unauthenticated remote attacker to achieve cross-tenant remote code execution, model theft, and poisoning via pre-creating predictably named Cloud Storage buckets (Bucket Squatting). This vulnerability was patched and no customer action is needed. Affected versions
1.100.0
1.101.0
1.102.0
1.103.0
1.104.0
1.105.0
1.106.0
1.107.0
1.108.0
1.109.0
1.110.0
1.111.0
+ 120 more Show less
1.112.0
1.113.0
1.114.0
1.115.0
1.116.0
1.117.0
1.118.0
1.119.0
1.120.0
1.121.0
1.122.0
1.123.0
1.124.0
1.125.0
1.126.0
1.126.1
1.127.0
1.128.0
1.129.0
1.130.0
1.131.0
1.132.0
1.21.0
1.22.0
1.22.1
1.23.0
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.28.0
1.28.1
1.29.0
1.30.0
1.30.1
1.31.0
1.31.1
1.32.0
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.36.1
1.36.2
1.36.3
1.36.4
1.37.0
1.38.0
1.38.1
1.39.0
1.40.0
1.41.0
1.42.0
1.42.1
1.43.0
1.44.0
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.50.0
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.0
1.59.0
1.60.0
1.61.0
1.62.0
1.63.0
1.64.0
1.65.0
1.66.0
1.67.0
1.67.1
1.68.0
1.69.0
1.70.0
1.71.0
1.71.1
1.72.0
1.73.0
1.74.0
1.75.0
1.76.0
1.77.0
1.78.0
1.79.0
1.80.0
1.81.0
1.82.0
1.83.0
1.84.0
1.85.0
1.86.0
1.87.0
1.88.0
1.89.0
1.90.0
1.91.0
1.92.0
1.93.0
1.93.1
1.94.0
1.95.0
1.95.1
1.96.0
1.97.0
1.98.0
1.99.0
Fixed in
1.133.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-2472
PYSEC-2026-2499
GHSA-qv8j-hgpc-vrq8
Jul 13, 2026
Google Cloud Vertex AI SDK affected by Stored Cross-Site Scripting (XSS)
Critical
Network
Low
Low
Stored Cross-Site Scripting (XSS) in the _genai/_evals_visualization component of Google Cloud Vertex AI SDK (google-cloud-aiplatform) versions from 1.98.0 up to (but not including) 1.131.0 allows an unauthenticated remote attacker to execute arbitrary JavaScript in a victim's Jupyter or Colab environment via injecting script escape sequences into model evaluation results or dataset JSON data. Affected versions
1.100.0
1.101.0
1.102.0
1.103.0
1.104.0
1.105.0
1.106.0
1.107.0
1.108.0
1.109.0
1.110.0
1.111.0
+ 22 more Show less
1.112.0
1.113.0
1.114.0
1.115.0
1.116.0
1.117.0
1.118.0
1.119.0
1.120.0
1.121.0
1.122.0
1.123.0
1.124.0
1.125.0
1.126.0
1.126.1
1.127.0
1.128.0
1.129.0
1.130.0
1.98.0
1.99.0
Fixed in
1.131.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.128.0
minor
2 CVEs
CVE-2026-2473
PYSEC-2026-2500
GHSA-wh2j-26j7-9728
Jul 13, 2026
Google Cloud Vertex AI has a a vulnerability involving predictable bucket naming
Critical
Network
Low
None
Predictable bucket naming in Vertex AI Experiments in Google Cloud Vertex AI from version 1.21.0 up to (but not including) 1.133.0 on Google Cloud Platform allows an unauthenticated remote attacker to achieve cross-tenant remote code execution, model theft, and poisoning via pre-creating predictably named Cloud Storage buckets (Bucket Squatting). This vulnerability was patched and no customer action is needed. Affected versions
1.100.0
1.101.0
1.102.0
1.103.0
1.104.0
1.105.0
1.106.0
1.107.0
1.108.0
1.109.0
1.110.0
1.111.0
+ 120 more Show less
1.112.0
1.113.0
1.114.0
1.115.0
1.116.0
1.117.0
1.118.0
1.119.0
1.120.0
1.121.0
1.122.0
1.123.0
1.124.0
1.125.0
1.126.0
1.126.1
1.127.0
1.128.0
1.129.0
1.130.0
1.131.0
1.132.0
1.21.0
1.22.0
1.22.1
1.23.0
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.28.0
1.28.1
1.29.0
1.30.0
1.30.1
1.31.0
1.31.1
1.32.0
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.36.1
1.36.2
1.36.3
1.36.4
1.37.0
1.38.0
1.38.1
1.39.0
1.40.0
1.41.0
1.42.0
1.42.1
1.43.0
1.44.0
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.50.0
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.0
1.59.0
1.60.0
1.61.0
1.62.0
1.63.0
1.64.0
1.65.0
1.66.0
1.67.0
1.67.1
1.68.0
1.69.0
1.70.0
1.71.0
1.71.1
1.72.0
1.73.0
1.74.0
1.75.0
1.76.0
1.77.0
1.78.0
1.79.0
1.80.0
1.81.0
1.82.0
1.83.0
1.84.0
1.85.0
1.86.0
1.87.0
1.88.0
1.89.0
1.90.0
1.91.0
1.92.0
1.93.0
1.93.1
1.94.0
1.95.0
1.95.1
1.96.0
1.97.0
1.98.0
1.99.0
Fixed in
1.133.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-2472
PYSEC-2026-2499
GHSA-qv8j-hgpc-vrq8
Jul 13, 2026
Google Cloud Vertex AI SDK affected by Stored Cross-Site Scripting (XSS)
Critical
Network
Low
Low
Stored Cross-Site Scripting (XSS) in the _genai/_evals_visualization component of Google Cloud Vertex AI SDK (google-cloud-aiplatform) versions from 1.98.0 up to (but not including) 1.131.0 allows an unauthenticated remote attacker to execute arbitrary JavaScript in a victim's Jupyter or Colab environment via injecting script escape sequences into model evaluation results or dataset JSON data. Affected versions
1.100.0
1.101.0
1.102.0
1.103.0
1.104.0
1.105.0
1.106.0
1.107.0
1.108.0
1.109.0
1.110.0
1.111.0
+ 22 more Show less
1.112.0
1.113.0
1.114.0
1.115.0
1.116.0
1.117.0
1.118.0
1.119.0
1.120.0
1.121.0
1.122.0
1.123.0
1.124.0
1.125.0
1.126.0
1.126.1
1.127.0
1.128.0
1.129.0
1.130.0
1.98.0
1.99.0
Fixed in
1.131.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.127.0
minor
2 CVEs
CVE-2026-2473
PYSEC-2026-2500
GHSA-wh2j-26j7-9728
Jul 13, 2026
Google Cloud Vertex AI has a a vulnerability involving predictable bucket naming
Critical
Network
Low
None
Predictable bucket naming in Vertex AI Experiments in Google Cloud Vertex AI from version 1.21.0 up to (but not including) 1.133.0 on Google Cloud Platform allows an unauthenticated remote attacker to achieve cross-tenant remote code execution, model theft, and poisoning via pre-creating predictably named Cloud Storage buckets (Bucket Squatting). This vulnerability was patched and no customer action is needed. Affected versions
1.100.0
1.101.0
1.102.0
1.103.0
1.104.0
1.105.0
1.106.0
1.107.0
1.108.0
1.109.0
1.110.0
1.111.0
+ 120 more Show less
1.112.0
1.113.0
1.114.0
1.115.0
1.116.0
1.117.0
1.118.0
1.119.0
1.120.0
1.121.0
1.122.0
1.123.0
1.124.0
1.125.0
1.126.0
1.126.1
1.127.0
1.128.0
1.129.0
1.130.0
1.131.0
1.132.0
1.21.0
1.22.0
1.22.1
1.23.0
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.28.0
1.28.1
1.29.0
1.30.0
1.30.1
1.31.0
1.31.1
1.32.0
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.36.1
1.36.2
1.36.3
1.36.4
1.37.0
1.38.0
1.38.1
1.39.0
1.40.0
1.41.0
1.42.0
1.42.1
1.43.0
1.44.0
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.50.0
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.0
1.59.0
1.60.0
1.61.0
1.62.0
1.63.0
1.64.0
1.65.0
1.66.0
1.67.0
1.67.1
1.68.0
1.69.0
1.70.0
1.71.0
1.71.1
1.72.0
1.73.0
1.74.0
1.75.0
1.76.0
1.77.0
1.78.0
1.79.0
1.80.0
1.81.0
1.82.0
1.83.0
1.84.0
1.85.0
1.86.0
1.87.0
1.88.0
1.89.0
1.90.0
1.91.0
1.92.0
1.93.0
1.93.1
1.94.0
1.95.0
1.95.1
1.96.0
1.97.0
1.98.0
1.99.0
Fixed in
1.133.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-2472
PYSEC-2026-2499
GHSA-qv8j-hgpc-vrq8
Jul 13, 2026
Google Cloud Vertex AI SDK affected by Stored Cross-Site Scripting (XSS)
Critical
Network
Low
Low
Stored Cross-Site Scripting (XSS) in the _genai/_evals_visualization component of Google Cloud Vertex AI SDK (google-cloud-aiplatform) versions from 1.98.0 up to (but not including) 1.131.0 allows an unauthenticated remote attacker to execute arbitrary JavaScript in a victim's Jupyter or Colab environment via injecting script escape sequences into model evaluation results or dataset JSON data. Affected versions
1.100.0
1.101.0
1.102.0
1.103.0
1.104.0
1.105.0
1.106.0
1.107.0
1.108.0
1.109.0
1.110.0
1.111.0
+ 22 more Show less
1.112.0
1.113.0
1.114.0
1.115.0
1.116.0
1.117.0
1.118.0
1.119.0
1.120.0
1.121.0
1.122.0
1.123.0
1.124.0
1.125.0
1.126.0
1.126.1
1.127.0
1.128.0
1.129.0
1.130.0
1.98.0
1.99.0
Fixed in
1.131.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.126.1
patch
2 CVEs
CVE-2026-2473
PYSEC-2026-2500
GHSA-wh2j-26j7-9728
Jul 13, 2026
Google Cloud Vertex AI has a a vulnerability involving predictable bucket naming
Critical
Network
Low
None
Predictable bucket naming in Vertex AI Experiments in Google Cloud Vertex AI from version 1.21.0 up to (but not including) 1.133.0 on Google Cloud Platform allows an unauthenticated remote attacker to achieve cross-tenant remote code execution, model theft, and poisoning via pre-creating predictably named Cloud Storage buckets (Bucket Squatting). This vulnerability was patched and no customer action is needed. Affected versions
1.100.0
1.101.0
1.102.0
1.103.0
1.104.0
1.105.0
1.106.0
1.107.0
1.108.0
1.109.0
1.110.0
1.111.0
+ 120 more Show less
1.112.0
1.113.0
1.114.0
1.115.0
1.116.0
1.117.0
1.118.0
1.119.0
1.120.0
1.121.0
1.122.0
1.123.0
1.124.0
1.125.0
1.126.0
1.126.1
1.127.0
1.128.0
1.129.0
1.130.0
1.131.0
1.132.0
1.21.0
1.22.0
1.22.1
1.23.0
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.28.0
1.28.1
1.29.0
1.30.0
1.30.1
1.31.0
1.31.1
1.32.0
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.36.1
1.36.2
1.36.3
1.36.4
1.37.0
1.38.0
1.38.1
1.39.0
1.40.0
1.41.0
1.42.0
1.42.1
1.43.0
1.44.0
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.50.0
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.0
1.59.0
1.60.0
1.61.0
1.62.0
1.63.0
1.64.0
1.65.0
1.66.0
1.67.0
1.67.1
1.68.0
1.69.0
1.70.0
1.71.0
1.71.1
1.72.0
1.73.0
1.74.0
1.75.0
1.76.0
1.77.0
1.78.0
1.79.0
1.80.0
1.81.0
1.82.0
1.83.0
1.84.0
1.85.0
1.86.0
1.87.0
1.88.0
1.89.0
1.90.0
1.91.0
1.92.0
1.93.0
1.93.1
1.94.0
1.95.0
1.95.1
1.96.0
1.97.0
1.98.0
1.99.0
Fixed in
1.133.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-2472
PYSEC-2026-2499
GHSA-qv8j-hgpc-vrq8
Jul 13, 2026
Google Cloud Vertex AI SDK affected by Stored Cross-Site Scripting (XSS)
Critical
Network
Low
Low
Stored Cross-Site Scripting (XSS) in the _genai/_evals_visualization component of Google Cloud Vertex AI SDK (google-cloud-aiplatform) versions from 1.98.0 up to (but not including) 1.131.0 allows an unauthenticated remote attacker to execute arbitrary JavaScript in a victim's Jupyter or Colab environment via injecting script escape sequences into model evaluation results or dataset JSON data. Affected versions
1.100.0
1.101.0
1.102.0
1.103.0
1.104.0
1.105.0
1.106.0
1.107.0
1.108.0
1.109.0
1.110.0
1.111.0
+ 22 more Show less
1.112.0
1.113.0
1.114.0
1.115.0
1.116.0
1.117.0
1.118.0
1.119.0
1.120.0
1.121.0
1.122.0
1.123.0
1.124.0
1.125.0
1.126.0
1.126.1
1.127.0
1.128.0
1.129.0
1.130.0
1.98.0
1.99.0
Fixed in
1.131.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.126.0
minor
2 CVEs
CVE-2026-2473
PYSEC-2026-2500
GHSA-wh2j-26j7-9728
Jul 13, 2026
Google Cloud Vertex AI has a a vulnerability involving predictable bucket naming
Critical
Network
Low
None
Predictable bucket naming in Vertex AI Experiments in Google Cloud Vertex AI from version 1.21.0 up to (but not including) 1.133.0 on Google Cloud Platform allows an unauthenticated remote attacker to achieve cross-tenant remote code execution, model theft, and poisoning via pre-creating predictably named Cloud Storage buckets (Bucket Squatting). This vulnerability was patched and no customer action is needed. Affected versions
1.100.0
1.101.0
1.102.0
1.103.0
1.104.0
1.105.0
1.106.0
1.107.0
1.108.0
1.109.0
1.110.0
1.111.0
+ 120 more Show less
1.112.0
1.113.0
1.114.0
1.115.0
1.116.0
1.117.0
1.118.0
1.119.0
1.120.0
1.121.0
1.122.0
1.123.0
1.124.0
1.125.0
1.126.0
1.126.1
1.127.0
1.128.0
1.129.0
1.130.0
1.131.0
1.132.0
1.21.0
1.22.0
1.22.1
1.23.0
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.28.0
1.28.1
1.29.0
1.30.0
1.30.1
1.31.0
1.31.1
1.32.0
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.36.1
1.36.2
1.36.3
1.36.4
1.37.0
1.38.0
1.38.1
1.39.0
1.40.0
1.41.0
1.42.0
1.42.1
1.43.0
1.44.0
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.50.0
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.0
1.59.0
1.60.0
1.61.0
1.62.0
1.63.0
1.64.0
1.65.0
1.66.0
1.67.0
1.67.1
1.68.0
1.69.0
1.70.0
1.71.0
1.71.1
1.72.0
1.73.0
1.74.0
1.75.0
1.76.0
1.77.0
1.78.0
1.79.0
1.80.0
1.81.0
1.82.0
1.83.0
1.84.0
1.85.0
1.86.0
1.87.0
1.88.0
1.89.0
1.90.0
1.91.0
1.92.0
1.93.0
1.93.1
1.94.0
1.95.0
1.95.1
1.96.0
1.97.0
1.98.0
1.99.0
Fixed in
1.133.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-2472
PYSEC-2026-2499
GHSA-qv8j-hgpc-vrq8
Jul 13, 2026
Google Cloud Vertex AI SDK affected by Stored Cross-Site Scripting (XSS)
Critical
Network
Low
Low
Stored Cross-Site Scripting (XSS) in the _genai/_evals_visualization component of Google Cloud Vertex AI SDK (google-cloud-aiplatform) versions from 1.98.0 up to (but not including) 1.131.0 allows an unauthenticated remote attacker to execute arbitrary JavaScript in a victim's Jupyter or Colab environment via injecting script escape sequences into model evaluation results or dataset JSON data. Affected versions
1.100.0
1.101.0
1.102.0
1.103.0
1.104.0
1.105.0
1.106.0
1.107.0
1.108.0
1.109.0
1.110.0
1.111.0
+ 22 more Show less
1.112.0
1.113.0
1.114.0
1.115.0
1.116.0
1.117.0
1.118.0
1.119.0
1.120.0
1.121.0
1.122.0
1.123.0
1.124.0
1.125.0
1.126.0
1.126.1
1.127.0
1.128.0
1.129.0
1.130.0
1.98.0
1.99.0
Fixed in
1.131.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.125.0
minor
2 CVEs
CVE-2026-2473
PYSEC-2026-2500
GHSA-wh2j-26j7-9728
Jul 13, 2026
Google Cloud Vertex AI has a a vulnerability involving predictable bucket naming
Critical
Network
Low
None
Predictable bucket naming in Vertex AI Experiments in Google Cloud Vertex AI from version 1.21.0 up to (but not including) 1.133.0 on Google Cloud Platform allows an unauthenticated remote attacker to achieve cross-tenant remote code execution, model theft, and poisoning via pre-creating predictably named Cloud Storage buckets (Bucket Squatting). This vulnerability was patched and no customer action is needed. Affected versions
1.100.0
1.101.0
1.102.0
1.103.0
1.104.0
1.105.0
1.106.0
1.107.0
1.108.0
1.109.0
1.110.0
1.111.0
+ 120 more Show less
1.112.0
1.113.0
1.114.0
1.115.0
1.116.0
1.117.0
1.118.0
1.119.0
1.120.0
1.121.0
1.122.0
1.123.0
1.124.0
1.125.0
1.126.0
1.126.1
1.127.0
1.128.0
1.129.0
1.130.0
1.131.0
1.132.0
1.21.0
1.22.0
1.22.1
1.23.0
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.28.0
1.28.1
1.29.0
1.30.0
1.30.1
1.31.0
1.31.1
1.32.0
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.36.1
1.36.2
1.36.3
1.36.4
1.37.0
1.38.0
1.38.1
1.39.0
1.40.0
1.41.0
1.42.0
1.42.1
1.43.0
1.44.0
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.50.0
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.0
1.59.0
1.60.0
1.61.0
1.62.0
1.63.0
1.64.0
1.65.0
1.66.0
1.67.0
1.67.1
1.68.0
1.69.0
1.70.0
1.71.0
1.71.1
1.72.0
1.73.0
1.74.0
1.75.0
1.76.0
1.77.0
1.78.0
1.79.0
1.80.0
1.81.0
1.82.0
1.83.0
1.84.0
1.85.0
1.86.0
1.87.0
1.88.0
1.89.0
1.90.0
1.91.0
1.92.0
1.93.0
1.93.1
1.94.0
1.95.0
1.95.1
1.96.0
1.97.0
1.98.0
1.99.0
Fixed in
1.133.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-2472
PYSEC-2026-2499
GHSA-qv8j-hgpc-vrq8
Jul 13, 2026
Google Cloud Vertex AI SDK affected by Stored Cross-Site Scripting (XSS)
Critical
Network
Low
Low
Stored Cross-Site Scripting (XSS) in the _genai/_evals_visualization component of Google Cloud Vertex AI SDK (google-cloud-aiplatform) versions from 1.98.0 up to (but not including) 1.131.0 allows an unauthenticated remote attacker to execute arbitrary JavaScript in a victim's Jupyter or Colab environment via injecting script escape sequences into model evaluation results or dataset JSON data. Affected versions
1.100.0
1.101.0
1.102.0
1.103.0
1.104.0
1.105.0
1.106.0
1.107.0
1.108.0
1.109.0
1.110.0
1.111.0
+ 22 more Show less
1.112.0
1.113.0
1.114.0
1.115.0
1.116.0
1.117.0
1.118.0
1.119.0
1.120.0
1.121.0
1.122.0
1.123.0
1.124.0
1.125.0
1.126.0
1.126.1
1.127.0
1.128.0
1.129.0
1.130.0
1.98.0
1.99.0
Fixed in
1.131.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.124.0
minor
2 CVEs
CVE-2026-2473
PYSEC-2026-2500
GHSA-wh2j-26j7-9728
Jul 13, 2026
Google Cloud Vertex AI has a a vulnerability involving predictable bucket naming
Critical
Network
Low
None
Predictable bucket naming in Vertex AI Experiments in Google Cloud Vertex AI from version 1.21.0 up to (but not including) 1.133.0 on Google Cloud Platform allows an unauthenticated remote attacker to achieve cross-tenant remote code execution, model theft, and poisoning via pre-creating predictably named Cloud Storage buckets (Bucket Squatting). This vulnerability was patched and no customer action is needed. Affected versions
1.100.0
1.101.0
1.102.0
1.103.0
1.104.0
1.105.0
1.106.0
1.107.0
1.108.0
1.109.0
1.110.0
1.111.0
+ 120 more Show less
1.112.0
1.113.0
1.114.0
1.115.0
1.116.0
1.117.0
1.118.0
1.119.0
1.120.0
1.121.0
1.122.0
1.123.0
1.124.0
1.125.0
1.126.0
1.126.1
1.127.0
1.128.0
1.129.0
1.130.0
1.131.0
1.132.0
1.21.0
1.22.0
1.22.1
1.23.0
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.28.0
1.28.1
1.29.0
1.30.0
1.30.1
1.31.0
1.31.1
1.32.0
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.36.1
1.36.2
1.36.3
1.36.4
1.37.0
1.38.0
1.38.1
1.39.0
1.40.0
1.41.0
1.42.0
1.42.1
1.43.0
1.44.0
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.50.0
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.0
1.59.0
1.60.0
1.61.0
1.62.0
1.63.0
1.64.0
1.65.0
1.66.0
1.67.0
1.67.1
1.68.0
1.69.0
1.70.0
1.71.0
1.71.1
1.72.0
1.73.0
1.74.0
1.75.0
1.76.0
1.77.0
1.78.0
1.79.0
1.80.0
1.81.0
1.82.0
1.83.0
1.84.0
1.85.0
1.86.0
1.87.0
1.88.0
1.89.0
1.90.0
1.91.0
1.92.0
1.93.0
1.93.1
1.94.0
1.95.0
1.95.1
1.96.0
1.97.0
1.98.0
1.99.0
Fixed in
1.133.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-2472
PYSEC-2026-2499
GHSA-qv8j-hgpc-vrq8
Jul 13, 2026
Google Cloud Vertex AI SDK affected by Stored Cross-Site Scripting (XSS)
Critical
Network
Low
Low
Stored Cross-Site Scripting (XSS) in the _genai/_evals_visualization component of Google Cloud Vertex AI SDK (google-cloud-aiplatform) versions from 1.98.0 up to (but not including) 1.131.0 allows an unauthenticated remote attacker to execute arbitrary JavaScript in a victim's Jupyter or Colab environment via injecting script escape sequences into model evaluation results or dataset JSON data. Affected versions
1.100.0
1.101.0
1.102.0
1.103.0
1.104.0
1.105.0
1.106.0
1.107.0
1.108.0
1.109.0
1.110.0
1.111.0
+ 22 more Show less
1.112.0
1.113.0
1.114.0
1.115.0
1.116.0
1.117.0
1.118.0
1.119.0
1.120.0
1.121.0
1.122.0
1.123.0
1.124.0
1.125.0
1.126.0
1.126.1
1.127.0
1.128.0
1.129.0
1.130.0
1.98.0
1.99.0
Fixed in
1.131.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.123.0
minor
2 CVEs
CVE-2026-2473
PYSEC-2026-2500
GHSA-wh2j-26j7-9728
Jul 13, 2026
Google Cloud Vertex AI has a a vulnerability involving predictable bucket naming
Critical
Network
Low
None
Predictable bucket naming in Vertex AI Experiments in Google Cloud Vertex AI from version 1.21.0 up to (but not including) 1.133.0 on Google Cloud Platform allows an unauthenticated remote attacker to achieve cross-tenant remote code execution, model theft, and poisoning via pre-creating predictably named Cloud Storage buckets (Bucket Squatting). This vulnerability was patched and no customer action is needed. Affected versions
1.100.0
1.101.0
1.102.0
1.103.0
1.104.0
1.105.0
1.106.0
1.107.0
1.108.0
1.109.0
1.110.0
1.111.0
+ 120 more Show less
1.112.0
1.113.0
1.114.0
1.115.0
1.116.0
1.117.0
1.118.0
1.119.0
1.120.0
1.121.0
1.122.0
1.123.0
1.124.0
1.125.0
1.126.0
1.126.1
1.127.0
1.128.0
1.129.0
1.130.0
1.131.0
1.132.0
1.21.0
1.22.0
1.22.1
1.23.0
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.28.0
1.28.1
1.29.0
1.30.0
1.30.1
1.31.0
1.31.1
1.32.0
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.36.1
1.36.2
1.36.3
1.36.4
1.37.0
1.38.0
1.38.1
1.39.0
1.40.0
1.41.0
1.42.0
1.42.1
1.43.0
1.44.0
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.50.0
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.0
1.59.0
1.60.0
1.61.0
1.62.0
1.63.0
1.64.0
1.65.0
1.66.0
1.67.0
1.67.1
1.68.0
1.69.0
1.70.0
1.71.0
1.71.1
1.72.0
1.73.0
1.74.0
1.75.0
1.76.0
1.77.0
1.78.0
1.79.0
1.80.0
1.81.0
1.82.0
1.83.0
1.84.0
1.85.0
1.86.0
1.87.0
1.88.0
1.89.0
1.90.0
1.91.0
1.92.0
1.93.0
1.93.1
1.94.0
1.95.0
1.95.1
1.96.0
1.97.0
1.98.0
1.99.0
Fixed in
1.133.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-2472
PYSEC-2026-2499
GHSA-qv8j-hgpc-vrq8
Jul 13, 2026
Google Cloud Vertex AI SDK affected by Stored Cross-Site Scripting (XSS)
Critical
Network
Low
Low
Stored Cross-Site Scripting (XSS) in the _genai/_evals_visualization component of Google Cloud Vertex AI SDK (google-cloud-aiplatform) versions from 1.98.0 up to (but not including) 1.131.0 allows an unauthenticated remote attacker to execute arbitrary JavaScript in a victim's Jupyter or Colab environment via injecting script escape sequences into model evaluation results or dataset JSON data. Affected versions
1.100.0
1.101.0
1.102.0
1.103.0
1.104.0
1.105.0
1.106.0
1.107.0
1.108.0
1.109.0
1.110.0
1.111.0
+ 22 more Show less
1.112.0
1.113.0
1.114.0
1.115.0
1.116.0
1.117.0
1.118.0
1.119.0
1.120.0
1.121.0
1.122.0
1.123.0
1.124.0
1.125.0
1.126.0
1.126.1
1.127.0
1.128.0
1.129.0
1.130.0
1.98.0
1.99.0
Fixed in
1.131.0
References
Updated Jul 13, 2026 · Source: OSV.dev |