AIIC AI Intelligence Centre

SOURCE-LINKED INTELLIGENCE

Google Cloud Agent Platform Release Notes: Security update for Server-Side Request Forgery (SSRF) in Agent Studio

Google Cloud Agent Platform Release Notes · article · Jul 20, 2026 · UTC

Security update for Server-Side Request Forgery (SSRF) in Agent Studio This release fixes a Server-Side Request Forgery (SSRF) vulnerability in the auto-generated /api-proxy backend endpoint for web applications created before July 1, 2026, using Agent Studio. If you downloaded, generated, or deployed web application code from Agent Studio before July 1, 2026, regenerate the app from Agent Studio and deploy the new version. For more information, see Quickstart: Deploy your Agent Studio prompt as a web application The updated backend code includes strict domain allowlist validation, ensuring that destination hostnames for the /api-proxy endpoint end with allowed Google Cloud domains, such as *-aiplatform.clients6.google.com

Read original source ↗ Open in workspace

recordType
page-entry
evidenceStatus
publisher-reported
region
Global

Evidence & attribution

First collected: 2026-09-23T00:41:11.323Z. This is not the publication date.