---
id: CVE-2026-79696
title: >-
  A Code Injection vulnerability in adk web in Google Cloud Agent Development
  Kit (ADK) for Python versions 2.0.0 through 2.6.0 on Python (OSS), Cloud Run,
  and GKE environments where pytest is installed allows an unauthenticated
  remote att…
summary: >-
  A Code Injection vulnerability in adk web in Google Cloud Agent Development
  Kit (ADK) for Python versions 2.0.0 through 2.6.0 on Python (OSS), Cloud Run,
  and GKE environments where pytest is installed allows an unauthenticated
  remote att…
severity: critical
cvss: 10
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/U:Amber'
cwe:
  - CWE-184
vendor: Google Cloud
product: Agent Development Kit (ADK) for Python
affected:
  - agent_development_kit_adk_for_python >= 2.0.0 < 2.7.0
published: '2026-09-09'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T21:17:04.820'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-79696'
references:
  - url: >-
      https://github.com/google/adk-python/commit/a16f6da3314b8dcd9925884cd6fc7fc9ffdd570d
    label: f45cbf4e-4146-4068-b7e1-655ffc2c548c
  - url: 'https://github.com/google/adk-python/releases/tag/v2.7.0'
    label: f45cbf4e-4146-4068-b7e1-655ffc2c548c
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-09-09T20:29:59.258522Z'
cvssSource: cna
ingestedAt: '2026-09-12T12:12:46.795Z'
epss: 0.00437
epssPercentile: 0.37351
---

## Overview

A Code Injection vulnerability in adk web in Google Cloud Agent Development Kit (ADK) for Python versions 2.0.0 through 2.6.0 on Python (OSS), Cloud Run, and GKE environments where pytest is installed allows an unauthenticated remote attacker to execute arbitrary code using a crafted test session replay.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
