Ground.News Google Vertex AI SDK Vulnerability Enables Code Execution via Bucket Squatting
Article Content
- •Vulnerability in Google Vertex AI SDK allows model hijacking and RCE.
- •Attackers exploit predictable bucket names to redirect model uploads.
- •Google has released patches and urged users to update their SDKs.
A vulnerability in Google's Vertex AI SDK for Python allowed attackers to hijack machine learning model uploads and execute arbitrary code within Google's infrastructure. Discovered by Palo Alto Networks' Unit 42, the flaw, termed 'Pickle in the Middle,' exploited predictable bucket naming and a lack of ownership verification. Attackers could create a bucket with the same name as a victim's expected staging bucket, leading to model uploads being redirected to the attacker's bucket. This scenario allowed the attacker to replace the model with a malicious version during a narrow time window. The exploit could lead to remote code execution due to the use of Python's pickle serialization format. Google has patched the vulnerability in SDK versions 1.144.0 and 1.148.0, urging users to update. No active exploitation has been reported in the wild.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (8)
Following this threat?
Track Google Cloud Platform in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical GitLab CVE-2026-85706 Exploited; Microsoft Issues Record 974 Patches A critical CVE-2026-85706 path-traversal vulnerability in GitLab (CVSS 10.0) was exploited in the wild just hours after its disclosure on September 12, 2026. Microsoft released its largest-ever patch batch, addressing 974 vulnerabilities, including several actively exploited Windows flaws. The GitLab flaw allows…