CVE-2026-19407: GCS Bucket Squatting leading to RCE in Gemini Enterprise Agent Platform Python SDK
Bucket Squatting in Google Cloud Gemini Enterprise Agent Platform SDK for Python versions prior to 1.166.1 allows an attacker to achieve Remote Code Execution (RCE) and tenant-project token theft.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Google Cloud Gemini Enterprise Agent Platform SDK for Pythonto a version that resolves this vulnerability.Fixed in 1.166.1 - Compensating control
Mitigate bucket-squatting related RCE/token theft by restricting access to the involved GCS buckets and ensuring bucket/object ownership matches the intended tenant project (e.g., enforce least-privilege IAM and prevent unauthorized bucket/object creation or takeover).
Event History
Frequently Asked Questions
Which SDK versions need to be upgraded?
Google Cloud Gemini Enterprise Agent Platform SDK for Python versions prior to 1.166.1 are affected. Upgrade to version 1.166.1 or later.
What could an attacker gain through successful exploitation?
Successful exploitation can lead to remote code execution and theft of tenant-project tokens.