Hey all ,
Few months back I found a command injection bug in Google Cloud shell
Since the title goes by the name "command injection" , you all might be thinking it as "normal Command injection which affects servers" but this vulnerability is quite different.
We can put this in different way as "Client Side command injection".
Lets get into the finding
While I was testing "console.cloud.google.com"