PT-2026-88902 · Google Cloud · Agent Development Kit (Adk) For Python
CVSS v4.0
10
Crítica
| Vetor | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber |
🚨 Google disclosed a CVSS 10.0 vulnerability in ADK for Python today.
The fixed version shipped 27 days ago.
CVE-2026-79696 affects specific conditions:
🔹 ADK for Python 2.0.0 through 2.6.0
🔹 The adk web development interface
🔹 Environments where pytest is installed
🔹 Network access to the affected path
Google advises upgrading to version 2.7.0 or later and keeping adk web off the network.
An inventory result containing “Google ADK” does not prove exposure. Teams need to check the running interpreter, deployed package version, listening address and actual network route.
The main lesson is that agent security starts before the model. Development interfaces and configuration loaders can carry host-level authority.
#GoogleADK #CVE #AISecurity #AgentSecurity #ApplicationSecurity #DevSecOps #CyberSecurity
Correção
RCE
Incomplete List of Disallowed Inputs
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Agent Development Kit (Adk) For Python