logo

Google Vertex AI SDK Flaw Let Attackers Hijack Model Uploads via Bucket Squatting

ID: 93629e69-2202-57a9-9134-c07e6e1617fd

STIX ID: report--93629e69-2202-57a9-9134-c07e6e1617fd

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2026-06-16

Date Updated: 2026-06-17

Author: [email protected] (The Hacker News)

...
...

Palo Alto Networks Unit 42 discovered a predictable-bucket-name vulnerability in the Google Cloud Vertex AI Python SDK that allowed attackers who only knew a victim's project ID to create the expected staging bucket, receive model uploads, replace them with malicious pickle/joblib artifacts, and achieve code execution inside Vertex AI serving containers; Google patched the issue in google-cloud-aiplatform v1.148.0 and recommends setting an explicit staging_bucket and updating the SDK.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.