Impact
A code injection flaw in the adk web component of Google Cloud Agent Development Kit (ADK) for Python allows an unauthenticated attacker to trigger execution of arbitrary code. The flaw is exercised by carefully crafted test session replay data that bypasses an incomplete denylist, enabling the attacker to run code with the privileges of the adk web process. This provides full takeover of the environment where adk runs.
Affected Systems
Google Cloud Agent Development Kit (ADK) for Python versions 2.0.0 through 2.6.0, when deployed in Python (OSS), Cloud Run or GKE environments and when the pytest package is present. The vulnerability is present in the adk web service component and requires that the service be reachable to be exploitable.
Risk and Exploitability
The flaw carries a CVSS score of 10.0, indicating a critical severity that can compromise confidentiality, integrity, and availability of the target system. The EPSS score is not available, but the lack of any listed exploitation evidence does not diminish the potential risk given the open nature of the attack vector. Attackers can craft a replay of a test session to invoke code execution via the publicly exposed adk web interface, so exposure of adk web to a network is the primary prerequisite for exploitation. The vulnerability is not listed in the CISA KEV catalog, but its critical nature and remote execution capability demand immediate mitigation.
OpenCVE Enrichment