Impact
The vulnerability is an incorrect authorization flaw in the GitHub Trigger Comment Control feature of Google Cloud Build. It enables an attacker to inject or execute unreviewed code within the build environment by suppressing webhooks. The compromised build process could allow malicious code to run with the permissions of the build service, potentially leading to full system compromise.
Affected Systems
The affected product is Google Cloud Build on the Google Cloud Platform, specifically versions deployed prior to 24 June 2026. Any build environment using a pre‑patch version of Cloud Build is susceptible; post‑patch deployments are not affected.
Risk and Exploitability
With a CVSS score of 9.4, this vulnerability is classified as critical. Although EPSS data is not available, the lack of a KEV listing implies no current known exploitation. The attack vector is likely remote, via a malicious or compromised GitHub repository that can trigger suppressed webhooks, making this risk significant for organizations still running affected Cloud Build instances.
OpenCVE Enrichment