SafetyGoogle
Google's agent toolkit had a flaw rated 10 out of 10, reachable without logging in
CVSS 10the maximum severity score
CVE-2026-79696 is a code injection flaw in adk web, part of Google Cloud's Agent Development Kit for Python, versions 2.0.0 to 2.6.0, on OSS, Cloud Run and GKE deployments where pytest is installed. A crafted test session replay lets an unauthenticated remote attacker run arbitrary code. It carries a CVSS score of 10, the maximum, and was disclosed on 9 September. Anyone running an affected version should upgrade.