Tools AI Risk Radar ai-incident-0008
Incident record
Google's Agent Development Kit let an unauthenticated caller read files off the builder endpoint
- Severity
- High
- Status
- Patched
- Type
- Data Leak
- Target
- google/adk-python 1.9.0 to 1.21.0
- Actor
- researcher
- CVE
- CVE-2026-79707
What happened
A crafted file_path query parameter on the ADK builder endpoint allowed path traversal and arbitrary file read with no authentication, scored CVSS 4.0 8.7. The fix shipped in ADK 1.22.0 months before the CVE record reached NVD on 4 September 2026, so this is a retroactively catalogued flaw rather than a fresh outbreak.
Sources
- Fix commit, google/adk-pythongithub.com/google/adk-python/commit/6f259f08b3c45ad6050b8a93…
- NVD, CVE-2026-79707nvd.nist.gov/vuln/detail/CVE-2026-79707
One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026