gcp Google Cloud release notes ·

Gemini Enterprise Agent Platform Security Update

aigcpsecurity-advisoryengineer
security

A Server-Side Request Forgery (SSRF) vulnerability in Agent Studio's auto-generated API proxy backend has been fixed. This addresses a potential security risk for web applications generated before July 1, 2026. Users who created applications before this date should regenerate and redeploy their apps from Agent Studio to incorporate the security patch, which includes strict domain allowlist validation.

Security (1)
  • Gemini Enterprise Agent Platform Security update for Server-Side Request Forgery (SSRF) in Agent Studio

    Security update for Server-Side Request Forgery (SSRF) in Agent Studio This release fixes a Server-Side Request Forgery (SSRF) vulnerability in the auto-generated /api-proxy backend endpoint for web applications created before July 1, 2026, using Agent Studio. If you downloaded, generated, or deployed web application code from Agent Studio before July 1, 2026, regenerate the app from Agent Studio and deploy the new version. For more information, see Quickstart: Deploy your Agent Studio prompt as a web application The updated backend code includes strict domain allowlist validation, ensuring th

Read the original announcement →

https://docs.cloud.google.com/release-notes#July_20_2026

Related releases