CVE-2026-81867 Google Cloud Application Integration JavaScript Task 反序列化漏洞
影响已认证低权限用户可在共享生产服务器上执行任意代码
Google Cloud Application Integration 的 JavaScript Task 组件存在不可信数据反序列化漏洞。攻击者通过特制脚本绕过参数防护,在共享生产服务器上执行任意代码。该漏洞已于 2026 年 6 月 28 日修复。
影响范围
Google Cloud Platform 上 Google Cloud Application Integration 2026-06-28 之前的版本。
漏洞详情
漏洞类型为不可信数据反序列化。JavaScript Task 在处理用户提交的脚本时未充分校验,导致攻击者可绕过参数守卫注入恶意序列化数据,进而触发反序列化并在共享生产服务器上执行任意代码。
利用条件与风险
利用需具备标准权限的已认证账号,属于低权限用户越权提权,且影响共享生产环境,实战风险较高。
修复建议
官方已于 2026 年 6 月 28 日完成修复,客户无需采取额外操作;暂无公开的临时缓解措施。
A Deserialization of Untrusted Data vulnerability in the JavaScript Task in Google Cloud Application Integration versions prior to 2026-06-28 on Google Cloud Platform allows an authenticated user with standard permissions to run arbitrary code on the shared production servers using a specially crafted script bypassing param guards.
This vulnerability was patched on 28 June 2026, and no customer action is needed.