Skip to content

Builder upload YAML validation can be bypassed #5347

@TristanInSec

Description

@TristanInSec

The YAML validation in the builder upload endpoint does not fully restrict values that could resolve to arbitrary Python references at agent load time.

PR #5344 hardens the validation to reject these values.

Metadata

Metadata

Assignees

Labels

agent engine[Component] This issue is related to Vertex AI Agent Engineneeds review[Status] The PR/issue is awaiting review from the maintainer

Type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions