GHSA-qv8j-hgpc-vrq8

Suggest an improvement
Source
https://github.com/advisories/GHSA-qv8j-hgpc-vrq8
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-qv8j-hgpc-vrq8/GHSA-qv8j-hgpc-vrq8.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-qv8j-hgpc-vrq8
Aliases
  • CVE-2026-2472
Downstream
Published
2026-02-20T21:31:24Z
Modified
2026-02-20T22:51:43.405115Z
Severity
  • 8.6 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/U:Amber CVSS Calculator
Summary
Google Cloud Vertex AI SDK affected by Stored Cross-Site Scripting (XSS)
Details

Stored Cross-Site Scripting (XSS) in the genai/evals_visualization component of Google Cloud Vertex AI SDK (google-cloud-aiplatform) versions from 1.98.0 up to (but not including) 1.131.0 allows an unauthenticated remote attacker to execute arbitrary JavaScript in a victim's Jupyter or Colab environment via injecting script escape sequences into model evaluation results or dataset JSON data.

Database specific
{
    "nvd_published_at": "2026-02-20T20:25:24Z",
    "github_reviewed_at": "2026-02-20T22:41:44Z",
    "github_reviewed": true,
    "severity": "HIGH",
    "cwe_ids": [
        "CWE-79"
    ]
}
References

Affected packages

PyPI / google-cloud-aiplatform

Package

Name
google-cloud-aiplatform
View open source insights on deps.dev
Purl
pkg:pypi/google-cloud-aiplatform

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.98.0
Fixed
1.131.0

Affected versions

1.*
1.98.0
1.99.0
1.100.0
1.101.0
1.102.0
1.103.0
1.104.0
1.105.0
1.106.0
1.107.0
1.108.0
1.109.0
1.110.0
1.111.0
1.112.0
1.113.0
1.114.0
1.115.0
1.116.0
1.117.0
1.118.0
1.119.0
1.120.0
1.121.0
1.122.0
1.123.0
1.124.0
1.125.0
1.126.0
1.126.1
1.127.0
1.128.0
1.129.0
1.130.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-qv8j-hgpc-vrq8/GHSA-qv8j-hgpc-vrq8.json"