chore(deps): [ai] Update dependency google-cloud-aiplatform [SECURITY]#350
Open
renovate-bot wants to merge 1 commit intoGoogleCloudPlatform:mainfrom
Conversation
|
02593c5 to
2b5e3b9
Compare
2b5e3b9 to
ea932d8
Compare
…latform [SECURITY]
ea932d8 to
01a7541
Compare
copybara-service bot
pushed a commit
that referenced
this pull request
Mar 5, 2026
…latform [SECURITY] Import of github PR #350 from renovate-bot #350 This PR contains the following updates: [google-cloud-aiplatform](https://redirect.github.com/googleapis/python-aiplatform): `1.127.0` → `1.133.0` [google-cloud-aiplatform](https://redirect.github.com/googleapis/python-aiplatform): `1.137.0` → `1.138.0` [google-cloud-aiplatform](https://redirect.github.com/googleapis/python-aiplatform): `==1.74.0` → `==1.133.0` [google-cloud-aiplatform](https://redirect.github.com/googleapis/python-aiplatform): `1.135.0` → `1.136.0` [google-cloud-aiplatform](https://redirect.github.com/googleapis/python-aiplatform): `1.133.0` → `1.134.0` --- > [!WARNING] > Some dependencies could not be looked up. Check the [Dependency Dashboard](../issues/73) for more information. ### GitHub Vulnerability Alerts #### [CVE-2026-2472](https://nvd.nist.gov/vuln/detail/CVE-2026-2472) Stored Cross-Site Scripting (XSS) in the _genai/_evals_visualization component of Google Cloud Vertex AI SDK (google-cloud-aiplatform) versions from 1.98.0 up to (but not including) 1.131.0 allows an unauthenticated remote attacker to execute arbitrary JavaScript in a victim's Jupyter or Colab environment via injecting script escape sequences into model evaluation results or dataset JSON data. #### [CVE-2026-2473](https://nvd.nist.gov/vuln/detail/CVE-2026-2473) Predictable bucket naming in Vertex AI Experiments in Google Cloud Vertex AI from version 1.21.0 up to (but not including) 1.133.0 on Google Cloud Platform allows an unauthenticated remote attacker to achieve cross-tenant remote code execution, model theft, and poisoning via pre-creating predictably named Cloud Storage buckets (Bucket Squatting). This vulnerability was patched and no customer action is needed. --- ### Google Cloud Vertex AI SDK affected by Stored Cross-Site Scripting (XSS) [CVE-2026-2472](https://nvd.nist.gov/vuln/detail/CVE-2026-2472) / [GHSA-qv8j-hgpc-vrq8](https://redirect.github.com/advisories/GHSA-qv8j-hgpc-vrq8) --- ### Google Cloud Vertex AI has a a vulnerability involving predictable bucket naming [CVE-2026-2473](https://nvd.nist.gov/vuln/detail/CVE-2026-2473) / [GHSA-wh2j-26j7-9728](https://redirect.github.com/advisories/GHSA-wh2j-26j7-9728) --- ### Release Notes --- ### Commit Message(s): -- Change 1 of 1 by Mend Renovate <bot@renovateapp.com>: chore(deps): [fsi-quant-assistant] Update dependency google-cloud-aiplatform [SECURITY] GitOrigin-RevId: 5965c29dc058bf0461ce450181454e16bfe81ef8 Change-Id: Iccd02b1f4f89d945e29499973ca3bb2bd891716f
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
1.137.0→1.138.01.74.0→1.133.01.135.0→1.136.01.133.0→1.134.0Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Google Cloud Vertex AI has a a vulnerability involving predictable bucket naming
CVE-2026-2473 / GHSA-wh2j-26j7-9728
More information
Details
Predictable bucket naming in Vertex AI Experiments in Google Cloud Vertex AI from version 1.21.0 up to (but not including) 1.133.0 on Google Cloud Platform allows an unauthenticated remote attacker to achieve cross-tenant remote code execution, model theft, and poisoning via pre-creating predictably named Cloud Storage buckets (Bucket Squatting).
This vulnerability was patched and no customer action is needed.
Severity
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/U:ClearReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
GitHub Vulnerability Alerts
CVE-2026-2473
Predictable bucket naming in Vertex AI Experiments in Google Cloud Vertex AI from version 1.21.0 up to (but not including) 1.133.0 on Google Cloud Platform allows an unauthenticated remote attacker to achieve cross-tenant remote code execution, model theft, and poisoning via pre-creating predictably named Cloud Storage buckets (Bucket Squatting).
This vulnerability was patched and no customer action is needed.
Release Notes
googleapis/python-aiplatform (google-cloud-aiplatform)
v1.138.0Compare Source
Features
Bug Fixes
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.