Executive brief
Google Cloud Application Integration's JavaScript Task component is vulnerable to a code execution flaw that allows authenticated users to run arbitrary code on shared production servers. The vulnerability was patched on June 28, 2026, and all customers have been automatically updated. No further action is required from customers.
Technical details
A deserialization of untrusted data vulnerability in the JavaScript Task component allows an authenticated user with standard permissions to craft a malicious script that achieves remote code execution on shared production infrastructure. The attack requires authentication and user-controlled input (a crafted script), and results in arbitrary code execution with the privileges of the JavaScript Task runtime.
Affected products
- Google Cloud Application Integration prior to June 28, 2026
Timeline
- 2026-06-28: patched
- 2026-09-28: disclosed