A Code Injection vulnerability in adk web in Google Cloud Agent Development Kit (ADK) for Python versions 2.0.0 through 2.6.0 on Python (OSS), Cloud Run, and GKE environments where pytest is installed allows an unauthenticated remote attacker to execute arbitrary code using a crafted test session replay.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
Upgrade to google-adk 2.7.0 or later. Do not expose adk web to a network.
Workaround
No workaround given by the vendor.
References
History
Wed, 09 Sep 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Code Injection vulnerability in adk web in Google Cloud Agent Development Kit (ADK) for Python versions 2.0.0 through 2.6.0 on Python (OSS), Cloud Run, and GKE environments where pytest is installed allows an unauthenticated remote attacker to execute arbitrary code using a crafted test session replay. | |
| Title | Remote Code Execution in Google ADK for Python via Incomplete Standard Library Denylist | |
| Weaknesses | CWE-184 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GoogleCloud
Published:
Updated: 2026-09-09T08:16:50.511Z
Reserved: 2026-08-25T12:09:54.636Z
Link: CVE-2026-79696
No data.
Status : Awaiting Analysis
Published: 2026-09-09T09:17:11.223
Modified: 2026-09-09T15:38:39.083
Link: CVE-2026-79696
No data.
OpenCVE Enrichment
Updated: 2026-09-09T10:15:09Z
Weaknesses