YFarmX logoYFarmX

Tools AI Risk Radar ai-incident-0008

Incident record

Google's Agent Development Kit let an unauthenticated caller read files off the builder endpoint

Severity
High
Status
Patched
Type
Data Leak
Target
google/adk-python 1.9.0 to 1.21.0
Actor
researcher
CVE
CVE-2026-79707

What happened

A crafted file_path query parameter on the ADK builder endpoint allowed path traversal and arbitrary file read with no authentication, scored CVSS 4.0 8.7. The fix shipped in ADK 1.22.0 months before the CVE record reached NVD on 4 September 2026, so this is a retroactively catalogued flaw rather than a fresh outbreak.

Sources

One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026