Tools AI Risk Radar ai-incident-0082
Incident record
Google's Agent Development Kit took a replayed test session straight to code execution
- Severity
- Critical
- Status
- Patched
- Type
- Agent Hijack
- Target
- google/adk-python 2.0.0 to 2.6.0 where pytest is installed
- Actor
- researcher
- CVE
- CVE-2026-79696
What happened
On adk web installations where pytest is present, a crafted test-session replay dispatches a recorded function call straight to a tool resolved from an attacker's agent YAML, so naming a standard-library callable such as cProfile.run executes arbitrary code with no authentication. NVD scores it CVSS 3.1 10.0. The fix in v2.7.0 blocks the whole Python standard library from agent configs, replacing an incomplete denylist. This is Google's second ADK entry on this board, after the earlier builder-endpoint file read.
Sources
- ADK release v2.7.0github.com/google/adk-python/releases/tag/v2.7.0
- Fix commit, google/adk-pythongithub.com/google/adk-python/commit/a16f6da3314b8dcd9925884c…
One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026