Pyyan / News / 9 September 2026

SafetyGoogle

Google's agent toolkit had a flaw rated 10 out of 10, reachable without logging in

CVSS 10the maximum severity score

CVE-2026-79696 is a code injection flaw in adk web, part of Google Cloud's Agent Development Kit for Python, versions 2.0.0 to 2.6.0, on OSS, Cloud Run and GKE deployments where pytest is installed. A crafted test session replay lets an unauthenticated remote attacker run arbitrary code. It carries a CVSS score of 10, the maximum, and was disclosed on 9 September. Anyone running an affected version should upgrade.

CVE-2026-79696TheHackerWirefrom the source itself

Related

← All the news, newest first