{"id":"CVE-2026-79707","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-79707","summary":"A Path Traversal vulnerability in the builder endpoint in Google Cloud Agent Development Kit (ADK) versions 1.9.0 through 1.21.0 on Python allows an unauthenticated remote attacker…","details":"A Path Traversal vulnerability in the builder endpoint in Google Cloud Agent Development Kit (ADK) versions 1.9.0 through 1.21.0 on Python allows an unauthenticated remote attacker to read arbitrary files using a crafted file_path query parameter.","published":"2026-09-04T11:17:19.087","modified":"2026-09-04T11:17:19.087","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/google/adk-python/commit/6f259f08b3c45ad6050b8a93c9bd85913451ece6","label":"google/adk-python@6f259f0"},"references":[{"type":"WEB","url":"https://github.com/google/adk-python/blob/main/CHANGELOG.md#1220-2026-01-08"},{"type":"WEB","url":"https://github.com/google/adk-python/commit/6f259f08b3c45ad6050b8a93c9bd85913451ece6"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-09-04T11:17:19.087"}}