CVE Explorer
CVE-2026-18236
A vulnerability in the Agent Development Kit (ADK) allows for continuation forgery in tool confirmations. An attacker who is able to manipulate or inject events into the session history can execute unauthorized tools by forging a tool confirmation response. This is possible because the framework did not verify if the target tool was registered to the executing agent, did not validate if the tool actually required confirmation, and did not match the confirmation arguments against the original too
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","platforms":["Python"],"product":"Google-ADK","vendor":"Google","versions":[{"status":"affected","version":"< 2.5.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:7eb74c9f3a29ab2fe196b6c28b65a695c2fb267a7341bac11a898b01a647e912 · sha256:9e9d490e64cd8fae… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":9.3,"baseSeverity":"CRITICAL","exploitMaturity":"PROOF_OF_CONCEPT","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"HIGH","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentia…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:7eb74c9f3a29ab2fe196b6c28b65a695c2fb267a7341bac11a898b01a647e912 · sha256:9e9d490e64cd8fae… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-863","description":"CWE-863 Incorrect Authorization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:7eb74c9f3a29ab2fe196b6c28b65a695c2fb267a7341bac11a898b01a647e912 · sha256:9e9d490e64cd8fae… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"url":"https://github.com/google/adk-python/commit/c03f333769feaeaa9fe8910fbe95cb9f2d513f54"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:7eb74c9f3a29ab2fe196b6c28b65a695c2fb267a7341bac11a898b01a647e912 · sha256:9e9d490e64cd8fae… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.