A vulnerability in Vertex AI Workbench allowed attackers to take over victims' Google Cloud projects through client-side SSRF.
The initial bug involved unauthorized access to authentication tokens, which was later fixed.
A bypass was later discovered (and also fixed) using open redirects in Feedburner and CSRF token manipulation.