CVE Tools

Google Vertex AI SDK Flaw Let Attackers Hijack Model Uploads via Bucket Squatting

The Hacker NewsBy The Hacker News

PatchVertex AI SDK for Python

Our summary

Google Cloud Vertex AI SDK for Python contained a bug that let an attacker with their own Google Cloud project and the victim’s project ID hijack model uploads and get code to execute in Google’s model serving infrastructure. The issue is in the SDK’s default temporary Cloud Storage bucket handling, enabling cross-tenant model replacement (notably for pickle/joblib-based models) and theft of OAuth tokens from the serving container; Unit 42 reported the risk and Google patched it in v1.148.0 (update from versions such as 1.139.0 and 1.140.0). No CVE has been published for this specific problem as of the article’s publication, but users should upgrade and explicitly set staging_bucket to a bucket they control.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store