Description
Bucket Squatting in Google Cloud Gemini Enterprise Agent Platform SDK for Python versions prior to 1.166.1 allows an attacker to achieve Remote Code Execution (RCE) and tenant-project token theft.
Published: 2026-09-15
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch
AI Analysis

Impact

This flaw arises from a bucket squatting issue in the Gemini Enterprise Agent Platform SDK for Python. By manipulating bucket names, an attacker can trick the agent into accessing an unintended bucket that contains malicious code. Following the hijack, the agent executes remote payloads and can also capture tenant‑project tokens, resulting in full RCE and credential theft.

Affected Systems

The vulnerable software is the Google Cloud Gemini Enterprise Agent Platform SDK for Python. Any installation running a version older than 1.165.1 is susceptible; versions 1.165.1 and newer have been patched.

Risk and Exploitability

The CVSS score of 7.7 indicates moderate‑to‑high severity. The EPSS score of < 1% indicates a very low exploitation probability, although it is not zero. The vulnerability is not listed in the CISA KEV catalog. The likely attack path involves an attacker naming a bucket that the agent will access, yielding code execution and token theft. The flaw is a classic bucket squatting CWE-330 scenario.

Generated by OpenCVE AI on September 20, 2026 at 16:32 UTC.

Remediation

Vendor Solution

Users of the google-cloud-aiplatform SDK should upgrade to version 1.165.1 or later, or ensure that an explicit staging_bucket belonging to their project is specified when calling Model.upload().


OpenCVE Recommended Actions

  • Upgrade the Google Cloud Gemini Enterprise Agent Platform SDK for Python to version 1.165.1 or later.
  • If upgrading is not feasible, configure Model.upload() to explicitly specify a staging_bucket that belongs to the user’s project, ensuring no bucket squatting can occur.
  • Remove or rename any buckets that could be used for squatting and audit bucket permissions to restrict access to legitimate tenant projects, implementing least‑privilege policies and regular permission reviews.

Generated by OpenCVE AI on September 20, 2026 at 16:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description Bucket Squatting in Google Cloud Gemini Enterprise Agent Platform SDK for Python versions prior to 1.166.1 allows an attacker to achieve Remote Code Execution (RCE) and tenant-project token theft.
Title GCS Bucket Squatting leading to RCE in Gemini Enterprise Agent Platform Python SDK
Weaknesses CWE-330
References
Metrics cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/U:Clear'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GoogleCloud

Published:

Updated: 2026-09-21T18:43:41.368Z

Reserved: 2026-08-10T08:36:31.688Z

Link: CVE-2026-19407

cve-icon Vulnrichment

Updated: 2026-09-21T18:43:38.263Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T16:17:08.380

Modified: 2026-09-21T19:17:04.443

Link: CVE-2026-19407

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:45:07Z

Weaknesses
  • CWE-330

    Use of Insufficiently Random Values