๐Ÿ” CVE Alert

CVE-2026-79707

UNKNOWN 0.0

Arbitrary File Read in Google Agent Development Kit (ADK)

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

A Path Traversal vulnerability in the builder endpoint in Google Cloud Agent Development Kit (ADK) versions 1.9.0 through 1.21.0 on Python allows an unauthenticated remote attacker to read arbitrary files using a crafted file_path query parameter.

CWE CWE-22
Vendor google cloud
Product agent development kit (adk)
Published Sep 4, 2026
Last Updated Sep 4, 2026
Stay Ahead of the Next One

Get instant alerts for google cloud agent development kit (adk)

Be the first to know when new unknown vulnerabilities affecting google cloud agent development kit (adk) are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Google Cloud / Agent Development Kit (ADK)
1.9.0 < 1.22.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/google/adk-python/blob/main/CHANGELOG.md#1220-2026-01-08 github.com: https://github.com/google/adk-python/commit/6f259f08b3c45ad6050b8a93c9bd85913451ece6

Credits

๐Ÿ” Hagai Sason