VDB
GCVE-110-CLOUD-2023-0061
GCVE-110-CLOUD-2023-0061
Advisory Published
This vulnerability chain exploits a Cross-Site Scripting (XSS) flaw (CVE-2021-41038) within the Theia IDE used in Google Vertex AI Workbench.
An attacker could inject malicious JavaScript code into the Theia IDE. This code could then be used to steal the OAuth token associated with the project's default Compute Engine service account,
because when a user-managed Vertex AI Workbench instance is created, it utilizes the project's default Compute Engine service account. At the time, this default service account had the Editor Role assigned by default.
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| GCP | Compute Engine | — | — |
| GCP | Cloud Vertex AI Workbench | — | — |
| GCP | Vertex AI | — | — |
| GCP | Cloud Services | — | — |
Aliases
Browse GCVE Records
67,893 records in the GCVE database · Updated August 16, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.