Google's Agent Development Kit for Python Carries a CVSS 10.0 Unauthenticated RCE via Test Session Replay
OffSeq Threat Radar·high signal
CVE-2026-79696, published September 9, is a code injection flaw in `adk web` affecting ADK for Python 2.0.0 through 2.6.0 wherever pytest is installed, including Cloud Run and GKE deployments. It scores a full 10.0: network vector, low complexity, no authentication and no user interaction, with high confidentiality, integrity and availability impact, triggered by a crafted test session replay. The root cause is CWE-184, an incomplete list of disallowed inputs.