Skip to content

Known CVE

Google ADK-Python - Unauthenticated Builder Endpoint

Google Agent Development Kit (ADK) 1.7.0 through 1.28.1 and 2.0.0a1 through 2.0.0a2 on Python (OSS), Cloud Run, and GKE contains a code injection and missing authentication vulnerability, letting unauthenticated remote attackers execute arbitrary code on the server, exploit requires no authentication.

CVE-2026-4810

Critical2026CVSS 9.3CWE-306CWE-94

cve2026 · adk · google · rce · unauth · code-injection

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website