Description
A Code Injection vulnerability in adk web in Google Cloud Agent Development Kit (ADK) for Python versions 2.0.0 through 2.6.0 on Python (OSS), Cloud Run, and GKE environments where pytest is installed allows an unauthenticated remote attacker to execute arbitrary code using a crafted test session replay.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Upgrade to google-adk 2.7.0 or later. Do not expose adk web to a network.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Wed, 09 Sep 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Code Injection vulnerability in adk web in Google Cloud Agent Development Kit (ADK) for Python versions 2.0.0 through 2.6.0 on Python (OSS), Cloud Run, and GKE environments where pytest is installed allows an unauthenticated remote attacker to execute arbitrary code using a crafted test session replay. | |
| Title | Remote Code Execution in Google ADK for Python via Incomplete Standard Library Denylist | |
| Weaknesses | CWE-184 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GoogleCloud
Published:
Updated: 2026-09-09T08:16:50.511Z
Reserved: 2026-08-25T12:09:54.636Z
Link: CVE-2026-79696
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses