VDB
GCVE-110-CLOUD-2020-0027
GCVE-110-CLOUD-2020-0027
Advisory Published
Google Cloudshell leveraged websockets without validating that the origin matched the current instance host.
An attacker could therefore host a CSWSH attack on a Cloudshell instance they own, disabling authentication via
access to the underlying VM. They could then start the OAuth process with a spoofed host header, using
phishing to get the target Cloud Shell user into following a redirection link, completing the OAuth process
and ending in successful CSWSH, which would allow the attacker to hijack the target user's requests.
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| GCP | GCP Cloudshell | — | — |
| GCP | Cloud Services | — | — |
Browse GCVE Records
74,366 records in the GCVE database · Updated July 23, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.