Impact
A code injection flaw combined with missing authentication allows an unauthenticated user to run arbitrary code on any server hosting the Google Agent Development Kit (ADK). The vulnerability, classified as CWE-306, means attackers can gain full control over the ADK instance, leading to compromise of confidentiality, integrity, and availability of the affected environment.
Affected Systems
Google Cloud’s Agent Development Kit (ADK) is affected. Vulnerable versions include 1.7.0 through 1.28.1 and 2.0.0a1 through 2.0.0a2. The flaw exists in Python (OSS) deployments, as well as when ADK is run on Cloud Run or GKE. Local installations of ADK Web are also impacted if they have not been upgraded.
Risk and Exploitability
The CVSS base score is 9.3, indicating a critical vulnerability. Although EPSS data is not available and the issue has not yet appeared in CISA’s KEV catalog, the lack of authentication combined with remote code execution capability means exploitation would be straightforward if the ADK service is exposed. Immediate patching is strongly recommended to mitigate the high risk of compromise.
OpenCVE Enrichment