PT-2026-85470 · Google · Cloud Agent Development Kit
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber |
Name of the Vulnerable Software and Affected Versions
Google Cloud Agent Development Kit (ADK) versions 1.9.0 through 1.21.0
Description
A Path Traversal issue exists in the builder endpoint. This allows an unauthenticated remote attacker to read arbitrary files by using a specially crafted
file path query parameter. Path Traversal is a flaw that allows an attacker to access files and directories that are stored outside the web root folder.Recommendations
Update Google Cloud Agent Development Kit (ADK) to a version later than 1.21.0.
Avoid using the
file path query parameter in the builder endpoint until the update is applied.Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cloud Agent Development Kit