CVE-2026-79696: Remote Code Execution in Google ADK for Python via Incomplete Standard Library Denylist
A Code Injection vulnerability in adk web in Google Cloud Agent Development Kit (ADK) for Python versions 2.0.0 through 2.6.0 on Python (OSS), Cloud Run, and GKE environments where pytest is installed allows an unauthenticated remote attacker to execute arbitrary code using a crafted test session replay.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
google-adkto a version that resolves this vulnerability.Fixed in 2.7.0 - Compensating control
Do not expose adk web to a network.
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Google ADK for Python versions 2.0.0 through 2.6.0 are affected on Python OSS, Cloud Run, and GKE environments when pytest is installed.
Does exploitation require authentication?
No. The vulnerability is described as exploitable by an unauthenticated remote attacker.
What does an attacker need to send to exploit it?
The attacker uses a crafted test session replay. Successful exploitation can result in arbitrary code execution.
What version addresses the issue?
The provided release reference identifies version 2.7.0.