---
id: CVE-2026-79707
title: >-
  A Path Traversal vulnerability in the builder endpoint in Google Cloud Agent
  Development Kit (ADK) versions 1.9.0 through 1.21.0 on Python allows an
  unauthenticated remote attacker to read arbitrary files using a crafted
  file_path query …
summary: >-
  A Path Traversal vulnerability in the builder endpoint in Google Cloud Agent
  Development Kit (ADK) versions 1.9.0 through 1.21.0 on Python allows an
  unauthenticated remote attacker to read arbitrary files using a crafted
  file_path query …
severity: none
cwe:
  - CWE-22
published: '2026-09-04'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T14:16:31.017'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-79707'
references:
  - url: >-
      https://github.com/google/adk-python/blob/main/CHANGELOG.md#1220-2026-01-08
    label: f45cbf4e-4146-4068-b7e1-655ffc2c548c
  - url: >-
      https://github.com/google/adk-python/commit/6f259f08b3c45ad6050b8a93c9bd85913451ece6
    label: f45cbf4e-4146-4068-b7e1-655ffc2c548c
tags:
  - nvd
epss: 0.00446
epssPercentile: 0.3817
ingestedAt: '2026-09-08T15:33:26.960Z'
---

## Overview

A Path Traversal vulnerability in the builder endpoint in Google Cloud Agent Development Kit (ADK) versions 1.9.0 through 1.21.0 on Python allows an unauthenticated remote attacker to read arbitrary files using a crafted file_path query parameter.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
