CVE-2026-79696
Dashboard / Vulnerabilities / CVE-2026-79696
CVE-2026-79696
Published: 9 Sept 2026Last Modified: 11 Sept 2026
Summary:
Details: A Code Injection vulnerability in adk web in Google Cloud Agent Development Kit (ADK) for Python versions 2.0.0 through 2.6.0 on Python (OSS), Cloud Run, and GKE environments where pytest is installed allows an unauthenticated remote attacker to execute arbitrary code using a crafted test session replay.
References: https://github.com/google/adk-python/releases/tag/v2.7.0, https://github.com/google/adk-python/commit/a16f6da3314b8dcd9925884cd6fc7fc9ffdd570d
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
Introduced- 0a290d574303ad79d25d7f2ecb5d118ff5118e95
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
