HIGH 8.7 NVD
CVE-2026-79707
A Path Traversal vulnerability in the builder endpoint in Google Cloud Agent Development Kit (ADK) versions 1.9.0 through 1.21.0 on Python allows an unauthentic
A Path Traversal vulnerability in the builder endpoint in Google Cloud Agent Development Kit (ADK) versions 1.9.0 through 1.21.0 on Python allows an unauthenticated remote attacker to read arbitrary files using a crafted file_path query parameter.
References
- https://github.com/google/adk-python/blob/main/CHANGELOG.md#1220-2026-01-08
- https://github.com/google/adk-python/commit/6f259f08b3c45ad6050b8a93c9bd85913451ece6
This high severity vulnerability with a CVSS score of 8.7 was published on 2026-09-04 via NVD.
vulnfeed aggregates 8217 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.