CVE-2026-79696

A Code Injection vulnerability in adk web in Google Cloud Agent Development Kit (ADK) for Python versions 2.0.0 through 2.6.0 on Python (OSS), Cloud Run, and GKE environments where pytest is installed allows an unauthenticated remote attacker to execute arbitrary code using a crafted test session replay.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-09-09 09:17

Updated : 2026-09-09 21:17


NVD link : CVE-2026-79696

Mitre link : CVE-2026-79696

CVE.ORG link : CVE-2026-79696


JSON object : View

Products Affected

No product.

CWE
CWE-184

Incomplete List of Disallowed Inputs