A Code Injection vulnerability in adk web in Google Cloud Agent Development Kit (ADK) for Python versions 2.0.0 through 2.6.0 on Python (OSS), Cloud Run, and GKE environments where pytest is installed allows an unauthenticated remote attacker to execute arbitrary code using a crafted test session replay.
Metrics
Affected Vendors & Products
References
History
Thu, 10 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Google Cloud
Google Cloud agent Development Kit (adk) |
|
| Vendors & Products |
Google Cloud
Google Cloud agent Development Kit (adk) |
Wed, 09 Sep 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Code Injection vulnerability in adk web in Google Cloud Agent Development Kit (ADK) for Python versions 2.0.0 through 2.6.0 on Python (OSS), Cloud Run, and GKE environments where pytest is installed allows an unauthenticated remote attacker to execute arbitrary code using a crafted test session replay. | |
| Title | Remote Code Execution in Google ADK for Python via Incomplete Standard Library Denylist | |
| Weaknesses | CWE-184 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GoogleCloud
Published: 2026-09-09T08:16:50.511Z
Updated: 2026-09-09T20:51:32.388Z
Reserved: 2026-08-25T12:09:54.636Z
Link: CVE-2026-79696
No data.
Status : Awaiting Analysis
Published: 2026-09-09T09:17:11.223
Modified: 2026-09-09T21:17:04.820
Link: CVE-2026-79696
No data.