Executive brief
A code injection and missing authentication vulnerability in Google Agent Development Kit (ADK) allows unauthenticated remote attackers to execute arbitrary code on the hosting server.
Affected products
- PyPI google-adk
Junglewise Threat Intelligence
CVE-2026-4810 · Severity: critical · CVSS 4 · Published 2026-04-13
Vendors: PyPI.
A code injection and missing authentication vulnerability in Google Agent Development Kit (ADK) allows unauthenticated remote attackers to execute arbitrary code on the hosting server.