CVE Database
/

CVE-2026-2472

Back to search

CVE-2026-2472

Published: Feb 20, 2026

Modified: Feb 27, 2026

PUBLISHED

Description

Stored Cross-Site Scripting (XSS) in the _genai/_evals_visualization component of Google Cloud Vertex AI SDK (google-cloud-aiplatform) versions from 1.98.0 up to (but not including) 1.131.0 allows an unauthenticated remote attacker to execute arbitrary JavaScript in a victim's Jupyter or Colab environment via injecting script escape sequences into model evaluation results or dataset JSON data.

VendorProductVersions

Google Cloud

Vertex AI SDK for Python

affected
1.98.0 - < 1.131.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now