CVE-2026-2472 is a stored cross-site scripting (XSS) vulnerability in the _genai/_evals_visualization component of the Google Cloud Vertex AI SDK (PyPI package: google-cloud-aiplatform). In versions 1.98.0 up to (but not including) 1.131.0, attacker-controlled content embedded in model evaluation results or dataset JSON can be rendered in Jupyter/Google Colab visualization workflows without sufficient output encoding/sanitization, allowing injected script escape sequences to be interpreted as executable JavaScript in the victim’s notebook environment.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
Repository purpose: a minimal proof-of-concept for CVE-2026-2472, described as an XSS issue affecting Google Cloud’s Vertex AI Python SDK visualization utilities used in Jupyter/Colab-style HTML rendering. Structure (5 files): - `CVE-2026-2472.py` (entry point): Builds a JSON string containing an attacker-controlled `prompt` value set to `</script><script>alert('XSS');</script>`. It passes this JSON into `vertexai._genai._evals_visualization._get_evaluation_html(...)` to generate a self-contained HTML report, then writes it to `xss_proof_local.html`. Opening that file in a browser demonstrates script execution. - `_evals_visualization.py`: A (mostly) upstream-looking copy of Google’s visualization helper. The key sink is `_get_evaluation_html(eval_result_json: str)`, which embeds `eval_result_json` directly into a JavaScript assignment: `const data = {eval_result_json};`. If `eval_result_json` contains `</script>...`, it can break out of the script tag and inject arbitrary script, yielding XSS. The HTML also loads third-party JS from jsDelivr (Marked and DOMPurify). - `payload.json`: Same payload and structure as used by the PoC script. - `README.md`: End-user oriented instructions (some references like `main.py`/`requirements.txt` are not present in the provided file list), plus links to releases/issues. - `.gitignore`: ignores `.venv`. Exploit capabilities: - Demonstrates HTML/JS injection (XSS) by crafting a malicious JSON field that is embedded unsafely into generated HTML/JavaScript. - Produces a reproducible local artifact (`xss_proof_local.html`) to show the impact. No active network exploitation is performed by the PoC itself; the only network-relevant observables are the CDN script includes in the generated HTML and documentation links.
Repository purpose: proof-of-concept for CVE-2026-2472, a stored XSS in Google Cloud Vertex AI Python SDK (google-cloud-aiplatform) visualization utilities (vertexai/_genai/_evals_visualization.py) affecting versions 1.98.0 up to but not including 1.131.0. Structure and key files: - CVE-2026-2472.py: Minimal PoC script. It builds a JSON string containing an XSS payload in the "prompt" field, calls vertexai._genai._evals_visualization._get_evaluation_html(s), and writes the resulting HTML to xss_proof_local.html. Opening/rendering that HTML triggers the injected script. - _evals_visualization.py: A (likely copied) vulnerable version of the SDK module showing the root cause. The HTML generator embeds attacker-controlled JSON directly into an inline <script> block (e.g., `const data = {eval_result_json};` and similar patterns), without escaping for HTML script context. This allows `</script>` sequences inside JSON string values to terminate the script tag and inject arbitrary HTML/JS. - payload.json: Same payload used by the PoC, demonstrating the minimal malicious JSON structure. - README.md: Explains affected versions, impact (JS execution in Jupyter/Colab), and how to reproduce locally. Exploit capabilities: - Achieves JavaScript execution (stored XSS) when a victim renders the generated evaluation/inference visualization HTML. - Demonstrates a script-tag break-out payload (`</script><script>...`) that bypasses JSON serialization safety because the sink is HTML <script> context, not a JSON parser. Notable network/third-party resources: - The generated HTML references external CDN scripts (marked.js and DOMPurify) via jsDelivr, which are fingerprintable endpoints but not attacker C2. No IPs/domains for exfiltration are present; the PoC uses a benign alert() payload. Overall: This is a local reproduction PoC for a client-side stored XSS in the SDK’s HTML report generation, not a remote RCE exploit. The practical attack scenario is an attacker influencing evaluation results/dataset content that later gets visualized by a user in an IPython/Jupyter/Colab environment running a vulnerable SDK version.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A stored cross-site scripting vulnerability in Google Cloud Vertex AI SDK's evaluation visualization component permits arbitrary JavaScript execution in a victim's Jupyter or Colab environment through malicious model evaluation results or dataset JSON data. It affects google-cloud-aiplatform versions 1.98.0 through versions before 1.131.0. The plugin rates it High, with CVSS v3 8.1 and CVSS v4 8.6, and reports that exploits are available. Updating to version 1.131.0 or later addresses the vulnerability.
A stored XSS vulnerability in the Google Cloud Vertex AI SDK (_genai/_evals_visualization) that can allow arbitrary JavaScript execution in a victim’s Jupyter/Colab environment by injecting malicious content into evaluation results or dataset JSON.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.