Junglewise Threat Intelligence

CVE-2026-79707: Google Cloud Agent Development Kit path traversal in builder endpoint

CVE-2026-79707 · Severity: info · Published 2026-09-04

Vendors: Google.

Executive brief

The Google Cloud Agent Development Kit (ADK) is a Python framework for building AI agents. A path traversal vulnerability in its builder endpoint allows unauthenticated attackers to read arbitrary files from the server by manipulating a file path parameter, potentially exposing sensitive configuration, source code, or credentials.

Technical details

A path traversal vulnerability exists in the builder endpoint of Google Cloud ADK versions 1.9.0 through 1.21.0. The vulnerability is triggered via a crafted file_path query parameter that is not properly sanitized, allowing directory traversal (e.g., "../../../etc/passwd" sequences). The endpoint is reachable over the network without authentication. An attacker can craft requests to read arbitrary files accessible to the application process. The issue was reported on 2026-09-04; patch availability is not yet confirmed in the provided references.

Affected products

  • Google Cloud Agent Development Kit 1.9.0 through 1.21.0

Timeline

  • 2026-09-04: disclosed

References