VDB

GCVE-110-CLOUD-2023-0061

GCVE-110-CLOUD-2023-0061
Advisory Published
Vulnetix · Advisory published January 15, 2023
This vulnerability chain exploits a Cross-Site Scripting (XSS) flaw (CVE-2021-41038) within the Theia IDE used in Google Vertex AI Workbench. An attacker could inject malicious JavaScript code into the Theia IDE. This code could then be used to steal the OAuth token associated with the project's default Compute Engine service account, because when a user-managed Vertex AI Workbench instance is created, it utilizes the project's default Compute Engine service account. At the time, this default service account had the Editor Role assigned by default.

Affected Products

VendorProductVersionsPlatforms
GCPCompute Engine
GCPCloud Vertex AI Workbench
GCPVertex AI
GCPCloud Services

References

advisory

Browse GCVE Records

67,893 records in the GCVE database · Updated August 16, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›