Skip to content

chore(deps): [ai] Update dependency google-cloud-aiplatform [SECURITY]#350

Open
renovate-bot wants to merge 1 commit intoGoogleCloudPlatform:mainfrom
renovate-bot:renovate/pypi-google-cloud-aiplatform-vulnerability
Open

chore(deps): [ai] Update dependency google-cloud-aiplatform [SECURITY]#350
renovate-bot wants to merge 1 commit intoGoogleCloudPlatform:mainfrom
renovate-bot:renovate/pypi-google-cloud-aiplatform-vulnerability

Conversation

@renovate-bot
Copy link
Contributor

@renovate-bot renovate-bot commented Feb 22, 2026

This PR contains the following updates:

Package Change Age Confidence
google-cloud-aiplatform 1.137.01.138.0 age confidence
google-cloud-aiplatform 1.74.01.133.0 age confidence
google-cloud-aiplatform 1.135.01.136.0 age confidence
google-cloud-aiplatform 1.133.01.134.0 age confidence

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Google Cloud Vertex AI has a a vulnerability involving predictable bucket naming

CVE-2026-2473 / GHSA-wh2j-26j7-9728

More information

Details

Predictable bucket naming in Vertex AI Experiments in Google Cloud Vertex AI from version 1.21.0 up to (but not including) 1.133.0 on Google Cloud Platform allows an unauthenticated remote attacker to achieve cross-tenant remote code execution, model theft, and poisoning via pre-creating predictably named Cloud Storage buckets (Bucket Squatting).

This vulnerability was patched and no customer action is needed.

Severity

  • CVSS Score: 7.7 / 10 (High)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/U:Clear

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).

GitHub Vulnerability Alerts

CVE-2026-2473

Predictable bucket naming in Vertex AI Experiments in Google Cloud Vertex AI from version 1.21.0 up to (but not including) 1.133.0 on Google Cloud Platform allows an unauthenticated remote attacker to achieve cross-tenant remote code execution, model theft, and poisoning via pre-creating predictably named Cloud Storage buckets (Bucket Squatting).

This vulnerability was patched and no customer action is needed.


Release Notes

googleapis/python-aiplatform (google-cloud-aiplatform)

v1.138.0

Compare Source

Features
  • Add support for BYO-dockerfile in AE deployment (7572601)
  • GenAI SDK client - Make operation polling interval configurable when creating agent engine sandbox (bf9e0ff)
  • GenAI SDK client(multimodal) - Support Assess Batch Prediction Resources for the multimodal datasets. (0fe5314)
  • GenAI SDK client(multimodal) - Support Assess Batch Prediction Validity for the multimodal datasets. (a63e8d5)
  • GenAI SDK client(multimodal) - Support Assess Tuning Validity for multimodal dataset. (12f5aa5)
  • Update the ADK template to export logs directly to Cloud Logging when OTEL_SEMCONV_STABILITY_OPT_IN is set to "gen_ai_latest_experimental". (82db4ad)
Bug Fixes
  • Refactor session retrieval fallback in _streaming_agent_run_with_events. (8aec754)

Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@forking-renovate forking-renovate bot added dependencies Pull requests that update a dependency file p0 SECURITY labels Feb 22, 2026
@forking-renovate
Copy link

forking-renovate bot commented Feb 22, 2026

⚠️ Artifact update problem

Renovate failed to update artifacts related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: projects/dataflow-gcs-to-alloydb/requirements.txt
Command failed: uv pip compile --generate-hashes requirements.in --upgrade-package=google-cloud-aiplatform==1.136.0
  × No solution found when resolving dependencies:
  ╰─▶ Because there is no version of betterproto==2.0.0b6 and
      envoy-data-plane==1.0.3 depends on betterproto==2.0.0b6, we can conclude
      that envoy-data-plane==1.0.3 cannot be used.
      And because only the following versions of envoy-data-plane are
      available:
          envoy-data-plane<=1.0.3
          envoy-data-plane>=2
      we can conclude that envoy-data-plane>=1.0.3,<2 cannot be used.
      And because apache-beam==2.71.0 depends on envoy-data-plane>=1.0.3,<2
      and you require apache-beam[gcp]==2.71.0, we can conclude that your
      requirements are unsatisfiable.

      hint: `betterproto` was requested with a pre-release marker (e.g.,
      betterproto==2.0.0b6), but pre-releases weren't enabled (try:
      `--prerelease=allow`)

File name: projects/dataflow-gcs-to-alloydb/requirements-dev.txt
Command failed: uv pip compile --generate-hashes requirements-dev.in --upgrade-package=google-cloud-aiplatform==1.136.0
  × No solution found when resolving dependencies:
  ╰─▶ Because there is no version of betterproto==2.0.0b6 and
      envoy-data-plane==1.0.3 depends on betterproto==2.0.0b6, we can conclude
      that envoy-data-plane==1.0.3 cannot be used.
      And because only the following versions of envoy-data-plane are
      available:
          envoy-data-plane<=1.0.3
          envoy-data-plane>=2
      we can conclude that envoy-data-plane>=1.0.3,<2 cannot be used.
      And because apache-beam==2.71.0 depends on envoy-data-plane>=1.0.3,<2
      and you require apache-beam[gcp]==2.71.0, we can conclude that your
      requirements are unsatisfiable.

      hint: `betterproto` was requested with a pre-release marker (e.g.,
      betterproto==2.0.0b6), but pre-releases weren't enabled (try:
      `--prerelease=allow`)

@renovate-bot renovate-bot added dependencies Pull requests that update a dependency file SECURITY p0 labels Feb 22, 2026
@renovate-bot renovate-bot force-pushed the renovate/pypi-google-cloud-aiplatform-vulnerability branch from 02593c5 to 2b5e3b9 Compare February 23, 2026 15:51
@renovate-bot renovate-bot force-pushed the renovate/pypi-google-cloud-aiplatform-vulnerability branch from 2b5e3b9 to ea932d8 Compare March 3, 2026 13:49
@renovate-bot renovate-bot force-pushed the renovate/pypi-google-cloud-aiplatform-vulnerability branch from ea932d8 to 01a7541 Compare March 4, 2026 08:57
copybara-service bot pushed a commit that referenced this pull request Mar 5, 2026
…latform [SECURITY]

Import of github PR #350 from renovate-bot
#350

This PR contains the following updates:

[google-cloud-aiplatform](https://redirect.github.com/googleapis/python-aiplatform): `1.127.0` → `1.133.0`
[google-cloud-aiplatform](https://redirect.github.com/googleapis/python-aiplatform): `1.137.0` → `1.138.0`
[google-cloud-aiplatform](https://redirect.github.com/googleapis/python-aiplatform): `==1.74.0` → `==1.133.0`
[google-cloud-aiplatform](https://redirect.github.com/googleapis/python-aiplatform): `1.135.0` → `1.136.0`
[google-cloud-aiplatform](https://redirect.github.com/googleapis/python-aiplatform): `1.133.0` → `1.134.0`

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency Dashboard](../issues/73) for more information.

### GitHub Vulnerability Alerts

#### [CVE-2026-2472](https://nvd.nist.gov/vuln/detail/CVE-2026-2472)

Stored Cross-Site Scripting (XSS) in the _genai/_evals_visualization component of Google Cloud Vertex AI SDK (google-cloud-aiplatform) versions from 1.98.0 up to (but not including) 1.131.0 allows an unauthenticated remote attacker to execute arbitrary JavaScript in a victim's Jupyter or Colab environment via injecting script escape sequences into model evaluation results or dataset JSON data.

#### [CVE-2026-2473](https://nvd.nist.gov/vuln/detail/CVE-2026-2473)

Predictable bucket naming in Vertex AI Experiments in Google Cloud Vertex AI from version 1.21.0 up to (but not including) 1.133.0 on Google Cloud Platform allows an unauthenticated remote attacker to achieve cross-tenant remote code execution, model theft, and poisoning via pre-creating predictably named Cloud Storage buckets (Bucket Squatting).

This vulnerability was patched and no customer action is needed.

---

### Google Cloud Vertex AI SDK affected by Stored Cross-Site Scripting (XSS)
[CVE-2026-2472](https://nvd.nist.gov/vuln/detail/CVE-2026-2472) / [GHSA-qv8j-hgpc-vrq8](https://redirect.github.com/advisories/GHSA-qv8j-hgpc-vrq8)

---

### Google Cloud Vertex AI has a a vulnerability involving predictable bucket naming
[CVE-2026-2473](https://nvd.nist.gov/vuln/detail/CVE-2026-2473) / [GHSA-wh2j-26j7-9728](https://redirect.github.com/advisories/GHSA-wh2j-26j7-9728)

---

### Release Notes

---

### Commit Message(s):

--
Change 1 of 1 by Mend Renovate <bot@renovateapp.com>:

chore(deps): [fsi-quant-assistant] Update dependency google-cloud-aiplatform [SECURITY]

GitOrigin-RevId: 5965c29dc058bf0461ce450181454e16bfe81ef8
Change-Id: Iccd02b1f4f89d945e29499973ca3bb2bd891716f
@renovate-bot renovate-bot changed the title chore(deps): [fsi-quant-assistant] Update dependency google-cloud-aiplatform [SECURITY] chore(deps): [ai] Update dependency google-cloud-aiplatform [SECURITY] Mar 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file p0 SECURITY

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant