Impact
This flaw arises from a bucket squatting issue in the Gemini Enterprise Agent Platform SDK for Python. By manipulating bucket names, an attacker can trick the agent into accessing an unintended bucket that contains malicious code. Following the hijack, the agent executes remote payloads and can also capture tenant‑project tokens, resulting in full RCE and credential theft.
Affected Systems
The vulnerable software is the Google Cloud Gemini Enterprise Agent Platform SDK for Python. Any installation running a version older than 1.165.1 is susceptible; versions 1.165.1 and newer have been patched.
Risk and Exploitability
The CVSS score of 7.7 indicates moderate‑to‑high severity. The EPSS score of < 1% indicates a very low exploitation probability, although it is not zero. The vulnerability is not listed in the CISA KEV catalog. The likely attack path involves an attacker naming a bucket that the agent will access, yielding code execution and token theft. The flaw is a classic bucket squatting CWE-330 scenario.
OpenCVE Enrichment