Google Cloud Application Integration JavaScript sandbox escape
Attack Techniques & MethodsYesterday, 12:37
Google Cloud Application Integration lets users add JavaScript tasks to integration workflows. Legacy tasks ran on Rhino, a Java-based JavaScript engine, with a custom permission checker restricting access to the surrounding execution environment. An authorized workflow author combined permissions that remained available inside the sandbox to execute system commands as the task service account.
• Disabling the Rhino thread checks — The allowed permission set included
ReflectPermission("suppressAccessChecks"), which made private Java fields accessible through reflection. The script opened the private static COMMON_PERMISSIONS field and added AllPermission and modifyThread. This neutralized the checks applied to the untrusted Rhino thread, although a separate policy still restricted file and process access.• Escaping through a child JVM — The remaining policy allowed writes to
/tmp and execution of $JAVA_HOME/bin/java. The script saved a compiled Java class under /tmp and launched it with java -cp /tmp ExecuteCommands. The child JVM was not marked as an untrusted Rhino thread, so it could run system commands and return their output through a file and event.log().Exploitation required permission to create and run JavaScript tasks and affected only the former Rhino engine. Google tracks the issue as
CVE-2025-0982; new tasks moved to V8 in January 2025, and Rhino execution was fully blocked on March 30, 2026. The demonstrated result was command execution inside the managed task environment, not an escape to the underlying host or cluster control plane.Vulnerabilities
Researchers
Vendors
Products