Junglewise Threat Intelligence

CVE-2026-4810: Google Agent Development Kit code injection and missing authentication

CVE-2026-4810 · Severity: critical · CVSS 4 · Published 2026-04-13

Vendors: PyPI.

Executive brief

A code injection and missing authentication vulnerability in Google Agent Development Kit (ADK) allows unauthenticated remote attackers to execute arbitrary code on the hosting server.

Affected products

  • PyPI google-adk

References