Code Injection Vulnerability in Google Cloud Agent Development Kit
CVE-2026-79696
10CRITICAL
What is CVE-2026-79696?
A Code Injection vulnerability exists within the Google Cloud Agent Development Kit (ADK) for Python, specifically affecting versions 2.0.0 through 2.6.0. This flaw enables an unauthenticated remote attacker to exploit crafted test sessions, leading to arbitrary code execution across Python environments, including Cloud Run and Google Kubernetes Engine (GKE). The use of pytest in these setups amplifies the risk, rendering systems susceptible to unauthorized commands.
Affected Version(s)
Agent Development Kit (ADK) for Python 2.0.0 < 2.7.0
