CVE-2026-79707
Arbitrary File Read in Google Agent Development Kit (ADK)
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
A Path Traversal vulnerability in the builder endpoint in Google Cloud Agent Development Kit (ADK) versions 1.9.0 through 1.21.0 on Python allows an unauthenticated remote attacker to read arbitrary files using a crafted file_path query parameter.
| CWE | CWE-22 |
| Vendor | google cloud |
| Product | agent development kit (adk) |
| Published | Sep 4, 2026 |
| Last Updated | Sep 4, 2026 |
Stay Ahead of the Next One
Get instant alerts for google cloud agent development kit (adk)
Be the first to know when new unknown vulnerabilities affecting google cloud agent development kit (adk) are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Google Cloud / Agent Development Kit (ADK)
1.9.0 < 1.22.0
References
Credits
๐ Hagai Sason