Vibe Coding
CVE-2026-79707: unauthenticated path traversal in Google's Agent Development Kit builder endpoint
Published to NVD on 2026-09-04, this flaw lets an unauthenticated remote attacker read arbitrary files from a host running Google Cloud Agent Development Kit for Python, versions 1.9.0 through 1.21.0, via a crafted `file_path` query parameter on the builder endpoint. Thirteen minor versions are in range, which means most ADK deployments standing up the builder UI on a reachable interface are affected. If you exposed the ADK builder beyond localhost, treat any secrets on that host as read.
Source
↳ Follow the thread