google-adk@2.3.0

Agent Development Kit

  • latest version

    2.6.3

  • latest non vulnerable version

  • first published

    1 years ago

  • latest version published

    1 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the google-adk package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • C
    Incorrect Authorization

    google-adk is an Agent Development Kit

    Affected versions of this package are vulnerable to Incorrect Authorization via the request confirmation processing in request_confirmation.py. An attacker can execute unauthorized tools by injecting or manipulating session-history events to forge a tool confirmation response. The vulnerable code accepted a confirmation without verifying that the target tool was registered for the executing agent, without checking that the tool actually required confirmation, and without matching the confirmed arguments to the original tool call recorded in history. As a result, a user can trigger tool execution that was never legitimately confirmed, leading to unauthorized actions in the agent session.

    How to fix Incorrect Authorization?

    Upgrade google-adk to version 2.5.0 or higher.

    [,2.5.0)