Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade google-adk to 1.22.0 or later.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 04 Sep 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Google Cloud
Google Cloud agent Development Kit (adk) |
|
| Vendors & Products |
Google Cloud
Google Cloud agent Development Kit (adk) |
Fri, 04 Sep 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Path Traversal vulnerability in the builder endpoint in Google Cloud Agent Development Kit (ADK) versions 1.9.0 through 1.21.0 on Python allows an unauthenticated remote attacker to read arbitrary files using a crafted file_path query parameter. | |
| Title | Arbitrary File Read in Google Agent Development Kit (ADK) | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GoogleCloud
Published:
Updated: 2026-09-04T10:06:34.152Z
Reserved: 2026-08-25T12:56:19.104Z
Link: CVE-2026-79707
No data.
Status : Received
Published: 2026-09-04T11:17:19.087
Modified: 2026-09-04T11:17:19.087
Link: CVE-2026-79707
No data.
OpenCVE Enrichment
Updated: 2026-09-04T11:30:17Z