CVE-2026-2472 | Google Cloud Vertex AI SDK for Python up to 1.130.x _evals_visualization cross site scripting (gcp-2026-011)
A vulnerability marked as problematic has been reported in Google Cloud Vertex AI SDK for Python up to 1.130.x. The impacted element is an unknown function of the component _evals_visualization. Performing a manipulation results in cross site scripting.
This vulnerability is identified as CVE-2026-2472. The attack can be initiated remotely. There is not any exploit available.
This product is a managed service. This means that users are not able to maintain vulnerability countermeasures themselves. It is suggested to upgrade the affected component.