Remote Code Execution Vulnerability in Google Cloud Gemini Enterprise Agent Platform SDK for Python
CVE-2026-19407
7.7HIGH
What is CVE-2026-19407?
The Google Cloud Gemini Enterprise Agent Platform SDK for Python contains a vulnerability that allows attackers to exploit bucket squatting techniques, leading to the potential for remote code execution and the theft of tenant-project tokens. This issue is present in versions prior to 1.166.1, posing significant security risks for users relying on this SDK. It is crucial for users to update to the latest version to mitigate these risks.
Affected Version(s)
Gemini Enterprise Agent Platform SDK for Python 1.16.0 < 1.165.1
