CVE-2026-2472
Stored Cross-Site Scripting (XSS) in Vertex AI Python SDK Visualization
CVSS Score
8.1
EPSS Score
0.0%
EPSS Percentile
0th
Stored Cross-Site Scripting (XSS) in the _genai/_evals_visualization component of Google Cloud Vertex AI SDK (google-cloud-aiplatform) versions from 1.98.0 up to (but not including) 1.131.0 allows an unauthenticated remote attacker to execute arbitrary JavaScript in a victim's Jupyter or Colab environment via injecting script escape sequences into model evaluation results or dataset JSON data.
| CWE | CWE-79 |
| Vendor | google cloud |
| Product | vertex ai sdk for python |
| Published | Feb 20, 2026 |
| Last Updated | Jul 15, 2026 |
Stay Ahead of the Next One
Get instant alerts for google cloud vertex ai sdk for python
Be the first to know when new high vulnerabilities affecting google cloud vertex ai sdk for python are published β delivered to Slack, Telegram or Discord.
Get Free Alerts β
Free Β· No credit card Β· 60 sec setup
Affected Versions
Google Cloud / Vertex AI SDK for Python
1.98.0 < 1.131.0
References
docs.cloud.google.com: https://docs.cloud.google.com/support/bulletins#gcp-2026-011 github.com: https://github.com/JoshuaProvoste/CVE-2026-2472-Vertex-AI-SDK-Google-Cloud access.redhat.com: https://access.redhat.com/security/cve/CVE-2026-2472 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2441472 security.access.redhat.com: https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-2472.json access.redhat.com: https://access.redhat.com/errata/RHSA-2026:10184
Credits
π Din AsotiΔ