CVE-2026-79696
Remote Code Execution in Google ADK for Python via Incomplete Standard Library Denylist
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
A Code Injection vulnerability in adk web in Google Cloud Agent Development Kit (ADK) for Python versions 2.0.0 through 2.6.0 on Python (OSS), Cloud Run, and GKE environments where pytest is installed allows an unauthenticated remote attacker to execute arbitrary code using a crafted test session replay.
| CWE | CWE-184 |
| Vendor | google cloud |
| Product | agent development kit (adk) for python |
| Published | Sep 9, 2026 |
| Last Updated | Sep 9, 2026 |
Stay Ahead of the Next One
Get instant alerts for google cloud agent development kit (adk) for python
Be the first to know when new unknown vulnerabilities affecting google cloud agent development kit (adk) for python are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Google Cloud / Agent Development Kit (ADK) for Python
2.0.0 < 2.7.0
References
Credits
๐ Sanil Dulal