Google Cloud Vertex AI SDK affected by Stored Cross-Site Scripting (XSS)
High severity
GitHub Reviewed
Published
Feb 20, 2026
to the GitHub Advisory Database
•
Updated Feb 20, 2026
Package
Affected versions
>= 1.98.0, < 1.131.0
Patched versions
1.131.0
Description
Published by the National Vulnerability Database
Feb 20, 2026
Published to the GitHub Advisory Database
Feb 20, 2026
Reviewed
Feb 20, 2026
Last updated
Feb 20, 2026
Stored Cross-Site Scripting (XSS) in the _genai/_evals_visualization component of Google Cloud Vertex AI SDK (google-cloud-aiplatform) versions from 1.98.0 up to (but not including) 1.131.0 allows an unauthenticated remote attacker to execute arbitrary JavaScript in a victim's Jupyter or Colab environment via injecting script escape sequences into model evaluation results or dataset JSON data.
References