Skip to content
CriticalVulnerability

GHSA-rg7c-g689-fr3x: Google Agent Development Kit (ADK) has a Code Injection and Missing Authentication vulnerability

Published
Record updated
View JSON
Affected
  • google-adk >= 2.0.0a1, < 2.0.0a2, fixed in 2.0.0a2
  • google-adk >= 1.7.0, < 1.28.1, fixed in 1.28.1
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
2.2%

Summary

A Code Injection and Missing Authentication flaw in Google Agent Development Kit (ADK) versions 1.7.0 (and 2.0.0a1) through 1.28.1 (and 2.0.0a2) affects Python (OSS), Cloud Run and GKE deployments. An unauthenticated remote attacker can execute arbitrary code on the server hosting the ADK instance.

Mitigation

Patched in versions 1.28.1 and 2.0.0a2. Customers need to redeploy the upgraded ADK to their production environments, and users running ADK Web locally need to upgrade their local instance.