Remote Code Execution in Google ADK for Python via Incomplete Standard Library Denylist
28Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 10epss 0.4%
exploitation probability
0.4%top 63% of all CVEs
observed exploitation
nono source reports it
A Code Injection vulnerability in adk web in Google Cloud Agent Development Kit (ADK) for Python versions 2.0.0 through 2.6.0 on Python (OSS), Cloud Run, and GKE environments where pytest is installed allows an unauthenticated remote attacker to execute arbitrary code using a crafted test session replay.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/U:Amber
Affected products
Google Cloud · Agent Development Kit (ADK) for Python