Google · Cloud Agent Development Kit · CVE-2026-79707
**Name of the Vulnerable Software and Affected Versions**
Google Cloud Agent Development Kit (ADK) versions 1.9.0 through 1.21.0
**Description**
A Path Traversal issue exists in the builder endpoint. This allows an unauthenticated remote attacker to read arbitrary files by using a specially crafted `file path` query parameter. Path Traversal is a flaw that allows an attacker to access files and directories that are stored outside the web root folder.
**Recommendations**
Update Google Cloud Agent Development Kit (ADK) to a version later than 1.21.0.
Avoid using the `file path` query parameter in the builder endpoint until the update is applied.