CVE 9.3 CRITICAL

Remote Code Execution in Google Agent Development Kit (ADK)_CVE-2026-4810

9.3 / 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/U:Amber

Description

A Code Injection and Missing Authentication vulnerability in Google Agent Development Kit (ADK) versions 1.7.0 (and 2.0.0a1) through 1.28.1 (and 2.0.0a2) on Python (OSS), Cloud Run, and GKE allows an unauthenticated remote attacker to execute arbitrary code on the server hosting the ADK instance.

This vulnerability was patched in versions 1.28.1 and 2.0.0a2.


Customers need to redeploy the upgraded ADK to their production environments. In addition, if they are running ADK Web locally, they also need to upgrade their local instance.

AI Analysis

Code Injection and Missing Authentication vulnerability allowing remote code execution

Basic Information

ID CVE-2026-4810
Source GoogleCloud
Published Apr 13, 2026 at 08:35

Affected Product

Vendor Google Cloud
Product Agent Development Kit (ADK)
Version 1.7.0
Affected Versions Google Cloud Agent Development Kit (ADK) 1.7.0
Google Cloud Agent Development Kit (ADK) 2.0.0a1

CWE Classification

AI Assessment

AI Score 9.3 / 10
AI Severity Critical
Vendor Google Cloud
Product Agent Development Kit (ADK)
Version 1.7.0, 1.28.1, 2.0.0a1, 2.0.0a2

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.