Answer in brief
CVE-2026-2472 records a High severity (CVSS 8.1) vulnerability in Stored Cross-Site Scripting (XSS) in Vertex AI Python SDK Visualization. The current sources do not mark it as known exploited. The current feed maps Google Cloud/Vertex AI SDK for Python (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 8.1. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Google Cloud/Vertex AI SDK for Python (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Google Cloud/Vertex AI SDK for Pythongeneric | >=1.98.0 <1.131.0 | 1.131.0 |
Published upstream
Feb 20, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Jul 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Jul 15, 2026
Stored Cross-Site Scripting (XSS) in the _genai/_evals_visualization component of Google Cloud Vertex AI SDK (google-cloud-aiplatform) versions from 1.98.0 up to (but not including) 1.131.0 allows an unauthenticated remote attacker to execute arbitrary JavaScript in a victim's Jupyter or Colab environment via injecting script escape sequences into model evaluation results or dataset JSON data.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-2472 records a High severity (CVSS 8.1) vulnerability in Stored Cross-Site Scripting (XSS) in Vertex AI Python SDK Visualization. The current sources do not mark it as known exploited. The current feed maps Google Cloud/Vertex AI SDK for Python (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 8.1. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Google Cloud/Vertex AI SDK for Python (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Google Cloud/Vertex AI SDK for Pythongeneric | >=1.98.0 <1.131.0 | 1.131.0 |
Published upstream
Feb 20, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Jul 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Jul 15, 2026
Stored Cross-Site Scripting (XSS) in the _genai/_evals_visualization component of Google Cloud Vertex AI SDK (google-cloud-aiplatform) versions from 1.98.0 up to (but not including) 1.131.0 allows an unauthenticated remote attacker to execute arbitrary JavaScript in a victim's Jupyter or Colab environment via injecting script escape sequences into model evaluation results or dataset JSON data.
Quoted source text, attributed separately from HOL analysis.