PT-2026-92107 · Google · Gemini Enterprise Agent Platform Sdk For Python
CVSS v4.0
7.7
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Clear |
Name of the Vulnerable Software and Affected Versions
Google Cloud Gemini Enterprise Agent Platform SDK for Python versions prior to 1.166.1
Description
Bucket Squatting allows an attacker to achieve Remote Code Execution (RCE), which is the ability to execute arbitrary commands on a remote machine, and tenant-project token theft.
Recommendations
Update Google Cloud Gemini Enterprise Agent Platform SDK for Python to version 1.166.1 or later.
Fix
RCE
Use of Insufficiently Random Values
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gemini Enterprise Agent Platform Sdk For Python