Skip to content
Google Vertex AI SDK Vulnerability Enables Code Execution via Bucket Squatting

Google Vertex AI SDK Vulnerability Enables Code Execution via Bucket Squatting

First seen 17 Jun 2026, 17:10 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 18, 2026 at 16:45 UTC
  • Vulnerability in Google Vertex AI SDK allows model hijacking and RCE.
  • Attackers exploit predictable bucket names to redirect model uploads.
  • Google has released patches and urged users to update their SDKs.

A vulnerability in Google's Vertex AI SDK for Python allowed attackers to hijack machine learning model uploads and execute arbitrary code within Google's infrastructure. Discovered by Palo Alto Networks' Unit 42, the flaw, termed 'Pickle in the Middle,' exploited predictable bucket naming and a lack of ownership verification. Attackers could create a bucket with the same name as a victim's expected staging bucket, leading to model uploads being redirected to the attacker's bucket. This scenario allowed the attacker to replace the model with a malicious version during a narrow time window. The exploit could lead to remote code execution due to the use of Python's pickle serialization format. Google has patched the vulnerability in SDK versions 1.144.0 and 1.148.0, urging users to update. No active exploitation has been reported in the wild.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 93d ago How this analysis works

Timeline

2026-06-16
Vulnerability reported to Google
Unit 42 reported the flaw in the Vertex AI SDK through the bug bounty program, detailing the risks of model hijacking.
The Hacker News
2026-06-17
Google patches the vulnerability
Google released updates for the Vertex AI SDK to address the bucket squatting flaw, urging users to upgrade to versions 1.144.0 and 1.148.0.
Scworld
Recent
No exploitation reported
Unit 42 stated that there have been no confirmed instances of the vulnerability being exploited in the wild.
Ground.News

More articles in this cluster (8)

Following this threat?

Track Google Cloud Platform in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed