Vertex AI SDK bucket-squatting enables RCE
🛡️ We discovered a vulnerability in the Google Cloud Vertex AI Python SDK that allowed an attacker to hijack a model upload and poison it, enabling remote code execution (RCE) in a victim's serving infrastructure. The issue stems from a predictable default staging bucket name and a missing ownership check in the SDK. By creating the same deterministic bucket in their own project and granting broad permissions, an attacker could replace uploaded model artifacts within a short window before Vertex AI reads them. Google fixed the issue in google-cloud-aiplatform v1.148.0 released April 15, 2026; developers should upgrade to the patched SDK.
