CVE-2026-2472Disclosure

MEDIUMCVSS 8.6 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Stored Cross-Site Scripting (XSS) in the _genai/_evals_visualization component of Google Cloud Vertex AI SDK (google-cloud-aiplatform) versions from 1.98.0 up to (but not including) 1.131.0 allows an unauthenticated remote attacker to execute arbitrary JavaScript in a victim's Jupyter or Colab environment via injecting script escape sequences into model evaluation results or dataset JSON data.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 8 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 3 signals
  • PoC mentioned or linked in 4 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 8 signals
  • Disclosure: 3 classified signals
  • Peaked 5d ago at 2 mentions (2026-02-20); latest day: 1
  • 8 total mentions across 6 days

Deep dive

Activity timeline8 mentions / 6d
01122Mentions · 2026-02-20: 2Mentions · 2026-02-27: 2Mentions · 2026-02-28: 1Mentions · 2026-03-01: 1Mentions · 2026-03-04: 1Mentions · 2026-03-23: 1PoC Mentioned / Linked · 2026-02-27: 2PoC Mentioned / Linked · 2026-03-04: 1PoC Mentioned / Linked · 2026-03-23: 1Exploit Tool / Code · 2026-02-27: 2Exploit Tool / Code · 2026-03-23: 1Patch / Workaround · 2026-03-01: 1Technical Details · 2026-02-20: 2Technical Details · 2026-02-27: 2Technical Details · 2026-02-28: 1Technical Details · 2026-03-01: 1Technical Details · 2026-03-04: 1Technical Details · 2026-03-23: 102-2002-2702-2803-0103-0403-23
Signal classification4 categories
Disclosure
337.5%
Exploit
337.5%
PoC
112.5%
Patch
112.5%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-02-202
Disclosure2
2026-02-272
Exploit1PoC1
2026-02-281
Disclosure1
2026-03-011
Patch1
2026-03-041
Exploit1
2026-03-231
Exploit1
Full discourse8 posts
  • jp / kw0@JoshuaProvoste
    Exploit

    PoC/Exploit for CVE-2026-2472 – Unauthenticated Stored Cross-Site Scripting (XSS) in the Official Vertex AI SDK for Google Cloud https://github.com/JoshuaProvoste/CVE-2026-2472-Vertex-AI-SDK-Google-Cloud #BugBounty #Hacking #AI #GoogleCloud #VertexAI

    Post summary

    A PoC and exploit for CVE-2026-2472, a stored XSS in the Vertex AI SDK, has been published on GitHub.

    29035171.9K
    2.8K followersView on X
  • Clandestine@akaclandestine
    PoC

    GitHub - JoshuaProvoste/CVE-2026-2472-Vertex-AI-SDK-Google-Cloud: Technical PoC for CVE-2026-2472 (GCP-2026-011): Unauthenticated and Stored Cross-Site Scripting (XSS) in google-cloud-aiplatform _genai/_evals_visualization (Vertex AI Python SDK) https://github.com/JoshuaProvoste/CVE-2026-2472-Vertex-AI-SDK-Google-Cloud

    Post summary

    The text announces a GitHub repository containing a technical PoC that demonstrates an unauthenticated stored XSS vulnerability in the Vertex AI Python SDK, providing code and technical details but no patch or evidence of active exploitation.

    0301021.1K
    55.6K followersView on X
  • jp / kw0@JoshuaProvoste
    Exploit

    1️⃣ 0-click RCE Exploit for CVE-2024-10924 affecting over 4 million WordPress sites ⚙️ https://lnkd.in/dw__Mf3W 2️⃣ Unauthenticated Stored Cross-Site Scripting (XSS) for CVE-2026-2472 affecting the Google Cloud Vertex AI SDK ⚙️ https://lnkd.in/dR_2xKnD

    Post summary

    The post announces zero‑click RCE and unauthenticated XSS flaws with links that likely contain PoC code, yet it provides no evidence of active exploitation, patches, or false‑positive status.

    1001092
    2.8K followersView on X
  • VulnTracker@vuln_tracker
    Patch

    @Huntio We covered this in depth — including the connection to CVE-2026-2472 (stored XSS in Google's Vertex AI SDK). Two different vectors, same target: Google Cloud AI infrastructure. Full breakdown + actionable remediation steps: http://vulntracker.io/blog/google-maps-api-key-gemini-credential/

    Post summary

    The post references CVE-2026-2472, a stored XSS in Vertex AI SDK, and directs readers to a blog with remediation steps for Google Cloud AI infrastructure.

    0001068
    357 followersView on X
  • VulnTracker@vuln_tracker
    Disclosure

    This pairs with CVE-2026-2472 — stored XSS in Google's Vertex AI SDK affecting Jupyter/Colab environments. Rough week for Google Cloud AI security. Full CVE details + affected versions: http://vulntracker.io/cves/CVE-2026-2472 Audit your GCP API keys. Today.

    Post summary

    The post announces a stored XSS vulnerability (CVE-2026-2472) in Google's Vertex AI SDK that affects Jupyter/Colab environments, providing a link to full CVE details.

    1000093
    351 followersView on X
  • dbugs@ptdbugs
    Exploit

    Stored Cross-Site Scripting (XSS) in Vertex AI Python SDK Visualization CVE: CVE-2026-2472 PT-Identifier: PT-2026-21290 Vendor: Google Cloud Product: Vertex AI SDK for Python CVSS: 8.6 Credits: Din Asotić Description: Stored Cross-Site Scripting (XSS) in the _genai/_evals_visualization component of Google Cloud Vertex AI SDK (google-cloud-aiplatform) versions from 1.98.0 up to (but not including) 1.131.0 allows an unauthenticated remote attacker to execute arbitrary JavaScript in a victim's Jupyter or Colab environment via injecting script escape sequences into model evaluation results or dataset JSON data. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-2472 • https://docs.cloud.google.com/support/bulletins#gcp-2026-011 Exploit: https://github.com/JoshuaProvoste/CVE-2026-2472-Vertex-AI-SDK-Google-Cloud https://github.com/megafart1/CVE-2026-2472-Vertex-AI-SDK-Google-Cloud/tree/main #dbugs_vuln

    Post summary

    A stored XSS flaw in Vertex AI SDK is disclosed with detailed impact and target versions, accompanied by GitHub exploit repositories but no indication of a patch or active exploitation.

    0000089
    733 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2472 Stored Cross-Site Scripting (XSS) in the _genai/_evals_visualization component of Google Cloud Vertex AI SDK (google-cloud-aiplatform) versions from 1.98.0 up to (but n… https://www.cve.org/CVERecord?id=CVE-2026-2472

    Post summary

    The text announces a newly disclosed stored XSS vulnerability (CVE‑2026‑2472) in Google Cloud Vertex AI SDK, specifying affected components and versions, but does not provide PoC, exploit, or mitigation details.

    00000100
    56.4K followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-2472: Poisoned Notebooks: Stored XSS in Google Vertex AI SDK A critical Stored Cross-Site Scripting (XSS) vulnerability in the Google Cloud Vertex AI Python SDK allows attackers to execute arbitrary JavaScript within a victim's Jupyter or Col... https://cvereports.com/reports/CVE-2026-2472

    Post summary

    The text announces a critical stored XSS vulnerability (CVE‑2026‑2472) in the Google Vertex AI Python SDK that enables attackers to run arbitrary JavaScript in Jupyter notebooks.

    0000014
    26 followersView on X

Explore more