As cited
Copy frozen at (site build).
vulnerabilities
Pickle in the Middle - Hijacking Vertex AI Model Uploads for Cross-Tenant RCE
Unit 42 identified a vulnerability in Vertex AI's Python SDK that enables remote code execution through bucket squatting during model uploads. The flaw allows attackers to hijack model uploads across tenant boundaries. This affects the security posture of organizations using Vertex AI for machine learning operations.
Why it matters: Exploitable RCE vulnerability in a widely-used ML platform with cross-tenant impact requires immediate assessment and patching.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Pickle in the Middle - Hijacking Vertex AI Model Uploads for Cross-Tenant RCE
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Pickle in the Middle - Hijacking Vertex AI Model Uploads for Cross-Tenant RCE
Unit 42 identified a vulnerability in the Vertex artificial intelligence (AI) Python SDK that permits remote code execution (RCE) through bucket squatting during model uploads. An attacker can hijack the upload process to execute arbitrary code across tenant boundaries on Google Cloud's platform.
Why it matters: Organizations using Vertex AI for model deployment face cross-tenant RCE risk; security teams should audit SDK versions and model upload workflows for exposure.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Pickle in the Middle - Hijacking Vertex AI Model Uploads for Cross-Tenant RCE
Unit 42 identified a vulnerability in the Vertex artificial intelligence (AI) Python SDK that permits remote code execution (RCE) through bucket squatting during model uploads. An attacker can hijack the upload process to execute arbitrary code across tenant boundaries on Google Cloud's platform.
Why it matters: Organizations using Vertex AI for model deployment face cross-tenant RCE risk; security teams should audit SDK versions and model upload workflows for exposure.
- Source published
- First seen by Cybersecurity Tracker