Historical version

This is version 3, as it stood on . It is not what this organization currently publishes — read the current version.

GCP-2026-043

Google Version 3 imported change

Imported from official source

Published: 2026-06-24Description Description Severity Notes A vulnerability was found in Firebase Studio where the GetSignedGcsUrl RPC allowed authenticated users to list buckets and download deployment source code of other tenants. No action is required to mitigate this vulnerability as the fix has been deployed to the backend service. As a precautionary measure, users who stored sensitive information, such as API keys (for example, GEMINI_API_KEY), within their Firebase Studio workspace may choose to rotate these keys. For instructions, see the Firebase Studio troubleshooting guide. High CVE-2026-12715

This version

Version
3 of 4
Recorded
September 25, 2026 09:00
Change
Imported change
Content hash
1caa094565e359772dc14ee2f83af5a6
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.