CVE-2026-79696 PUBLISHED

Remote Code Execution in Google ADK for Python via Incomplete Standard Library Denylist

Assigner: GoogleCloud
Reserved: 25.08.2026 Published: 09.09.2026 Updated: 09.09.2026

A Code Injection vulnerability in adk web in Google Cloud Agent Development Kit (ADK) for Python versions 2.0.0 through 2.6.0 on Python (OSS), Cloud Run, and GKE environments where pytest is installed allows an unauthenticated remote attacker to execute arbitrary code using a crafted test session replay.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/U:Amber
CVSS Score: 10

Product Status

Vendor Google Cloud
Product Agent Development Kit (ADK) for Python
Versions Default: unaffected
  • affected from 2.0.0 to 2.7.0 (excl.)

Solutions

Upgrade to google-adk 2.7.0 or later. Do not expose adk web to a network.

Credits

  • Sanil Dulal reporter

References

Problem Types

  • CWE-184 Incomplete List of Disallowed Inputs CWE

Impacts

  • CAPEC-242 Code Injection