PT-2026-85470 · Google · Cloud Agent Development Kit

·

CVE-2026-79707

·

Published

2026-09-04

·

Updated

2026-09-04

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber
Name of the Vulnerable Software and Affected Versions Google Cloud Agent Development Kit (ADK) versions 1.9.0 through 1.21.0
Description A Path Traversal issue exists in the builder endpoint. This allows an unauthenticated remote attacker to read arbitrary files by using a specially crafted file path query parameter. Path Traversal is a flaw that allows an attacker to access files and directories that are stored outside the web root folder.
Recommendations Update Google Cloud Agent Development Kit (ADK) to a version later than 1.21.0. Avoid using the file path query parameter in the builder endpoint until the update is applied.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-79707

Affected Products

Cloud Agent Development Kit