CriticalVulnerability
GHSA-rg7c-g689-fr3x: Google Agent Development Kit (ADK) has a Code Injection and Missing Authentication vulnerability
- Identifiers
- CVE-2026-4810GHSA-rg7c-g689-fr3x
- Published
- Record updated
- Affected
- google-adk >= 2.0.0a1, < 2.0.0a2, fixed in 2.0.0a2
- google-adk >= 1.7.0, < 1.28.1, fixed in 1.28.1
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
- EPSS
- 2.2%
Summary
A Code Injection and Missing Authentication flaw in Google Agent Development Kit (ADK) versions 1.7.0 (and 2.0.0a1) through 1.28.1 (and 2.0.0a2) affects Python (OSS), Cloud Run and GKE deployments. An unauthenticated remote attacker can execute arbitrary code on the server hosting the ADK instance.
Mitigation
Patched in versions 1.28.1 and 2.0.0a2. Customers need to redeploy the upgraded ADK to their production environments, and users running ADK Web locally need to upgrade their local instance.
Affected packages in the Exposure Registry
Matched by package name and ecosystem. Each entry shows whether the package delegates to a language model and how many tracked packages depend on it.
- google-adkPyPILLM dependency since 2025-03-17 · 8 tracked dependents
Related items
- CriticalCVE-2026-90970: GitLab AI Gateway prompt template sandbox escape via crafted flow configurationSame vendor · NVD/CVE Database
- MediumCVE-2026-89278: GPTranslate WordPress plugin exposes plaintext API key to unauthenticated usersSame vendor · NVD/CVE Database
- CriticalCVE-2026-19407: Google Cloud Gemini Enterprise Agent Platform SDK for Python bucket squattingSame vendor · NVD/CVE Database
- HighCVE-2026-19486: A Server-Side Request Forgery (SSRF) vulnerability in Google Cloud Gemini Enterprise Agent Platform App Builder…Same vendor · NVD/CVE Database
- HighCVE-2026-13745: Gemini CLI code execution via untrusted .env files overriding GEMINI_CLI_HOMESame vendor · NVD/CVE Database