YFarmX logoYFarmX

Tools AI Risk Radar ai-incident-0082

Incident record

Google's Agent Development Kit took a replayed test session straight to code execution

Severity
Critical
Status
Patched
Type
Agent Hijack
Target
google/adk-python 2.0.0 to 2.6.0 where pytest is installed
Actor
researcher
CVE
CVE-2026-79696

What happened

On adk web installations where pytest is present, a crafted test-session replay dispatches a recorded function call straight to a tool resolved from an attacker's agent YAML, so naming a standard-library callable such as cProfile.run executes arbitrary code with no authentication. NVD scores it CVSS 3.1 10.0. The fix in v2.7.0 blocks the whole Python standard library from agent configs, replacing an incomplete denylist. This is Google's second ADK entry on this board, after the earlier builder-endpoint file read.

Sources

One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026