Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

A vulnerability in Google Cloud’s Vertex AI Python SDK (versions 1.139.0-1.140.0) allowed an unauthenticated attacker to hijack AI model uploads by claiming a predictable staging storage bucket before the victim’s upload occurred. Once claimed, the attacker could poison the bucket with a malicious payload, triggering remote code execution inside the victim’s model serving infrastructure when the model loaded. Organizations using the affected SDK versions to upload or serve AI models in Google Cloud are directly exposed until they upgrade to v1.148.0.

Author

Tech Jacks Solutions