Remote Code Execution in Google ADK for Python via Incomplete Standard Library Denylist
Summary
| CVE | CVE-2026-79696 |
|---|---|
| State | PUBLISHED |
| Assigner | GoogleCloud |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-09 09:17:11 UTC |
| Updated | 2026-09-09 21:17:04 UTC |
| Description | A Code Injection vulnerability in adk web in Google Cloud Agent Development Kit (ADK) for Python versions 2.0.0 through 2.6.0 on Python (OSS), Cloud Run, and GKE environments where pytest is installed allows an unauthenticated remote attacker to execute arbitrary code using a crafted test session replay. |
Risk And Classification
Primary CVSS: v4.0 10 CRITICAL from f45cbf4e-4146-4068-b7e1-655ffc2c548c
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber
EPSS: 0.004370000 probability, percentile 0.368970000 (date 2026-09-10)
Problem Types: CWE-184 | CWE-184 CWE-184 Incomplete List of Disallowed Inputs
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | f45cbf4e-4146-4068-b7e1-655ffc2c548c | Secondary | 10 | CRITICAL | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/C... |
| 4.0 | CNA | CVSS | 10 | CRITICAL | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/U:Amber |
CVSS v4.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowAttack Requirements
NonePrivileges Required
NoneUser Interaction
NoneConfidentiality
HighIntegrity
HighAvailability
HighSub Conf.
HighSub Integrity
HighSub Availability
HighCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Google Cloud | Agent Development Kit ADK For Python | affected 2.0.0 2.7.0 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| github.com/google/adk-python/releases/tag/v2.7.0 | f45cbf4e-4146-4068-b7e1-655ffc2c548c | github.com | |
| github.com/google/adk-python/commit/a16f6da3314b8dcd9925884cd6fc7fc9ffdd... | f45cbf4e-4146-4068-b7e1-655ffc2c548c | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Sanil Dulal (en)
Additional Advisory Data
Solutions
CNA: Upgrade to google-adk 2.7.0 or later. Do not expose adk web to a network.
There are currently no legacy QID mappings associated with this CVE.