VDB
GCVE-110-CLOUD-2024-0005
GCVE-110-CLOUD-2024-0005
Advisory Published
A vulnerability in GCP's Vertex AI service allows privilege escalation and unauthorized access to sensitive LLM models. Attackers can exfiltrate these models by exploiting misconfigurations in access controls and service bindings.
By exploiting custom job permissions, researchers were able to escalate their privileges and gain unauthorized access to all data services in the project.
In addition, deploying a poisoned model in Vertex AI led to the exfiltration of all other fine-tuned models, posing a proprietary and sensitive data exfiltration attack risk.
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| GCP | VertexAI | — | — |
| GCP | Vertex AI | — | — |
Browse GCVE Records
67,893 records in the GCVE database · Updated August 16, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.