CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Pickle in the Middle - Hijacking Vertex AI Model Uploads for Cross-Tenant RCE

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 339

As cited

Copy frozen at (site build).

vulnerabilities

Pickle in the Middle - Hijacking Vertex AI Model Uploads for Cross-Tenant RCE

Unit 42 identified a vulnerability in Vertex AI's Python SDK that enables remote code execution through bucket squatting during model uploads. The flaw allows attackers to hijack model uploads across tenant boundaries. This affects the security posture of organizations using Vertex AI for machine learning operations.

Why it matters: Exploitable RCE vulnerability in a widely-used ML platform with cross-tenant impact requires immediate assessment and patching.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Pickle in the Middle - Hijacking Vertex AI Model Uploads for Cross-Tenant RCE

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Pickle in the Middle - Hijacking Vertex AI Model Uploads for Cross-Tenant RCE

Unit 42 identified a vulnerability in the Vertex artificial intelligence (AI) Python SDK that permits remote code execution (RCE) through bucket squatting during model uploads. An attacker can hijack the upload process to execute arbitrary code across tenant boundaries on Google Cloud's platform.

Why it matters: Organizations using Vertex AI for model deployment face cross-tenant RCE risk; security teams should audit SDK versions and model upload workflows for exposure.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Pickle in the Middle - Hijacking Vertex AI Model Uploads for Cross-Tenant RCE

Unit 42 identified a vulnerability in the Vertex artificial intelligence (AI) Python SDK that permits remote code execution (RCE) through bucket squatting during model uploads. An attacker can hijack the upload process to execute arbitrary code across tenant boundaries on Google Cloud's platform.

Why it matters: Organizations using Vertex AI for model deployment face cross-tenant RCE risk; security teams should audit SDK versions and model upload workflows for exposure.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary