Critical Security Flaw Found in Google AI Agent Development Kit
A critical remote code execution vulnerability (CVE-2026-79696) with a CVSS score of 10.0 has been identified in Google Cloud's Agent Development Kit (ADK) for Python versions 2.0.0-2.6.0. This flaw allows unauthenticated attackers to execute arbitrary code via a crafted test session replay when pytest is installed. The vulnerability poses a severe risk to Python, Cloud Run, and GKE deployments utilizing the ADK.
Want more?
Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.