Intel

AIKIDO-2026-10558

google-adk is vulnerable to Information Disclosure

Information Disclosure Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Apr 27, 2026

41

Medium Risk

This Affects:

PYTHONgoogle-adk
1.23.0 - 1.28.1
Fixed in 1.29.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package may log plain-text OAuth credentials and tokens in the BigQuery Agent Analytics plugin, exposing secrets such as client_secret, access_token, refresh_token, id_token, api_key, and passwords. An attacker able to access BigQuery logs, exported telemetry, or downstream log storage could recover these credentials and use them to impersonate users, access protected services, or move laterally across connected systems.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

google-adk is vulnerable to Information Disclosure in versions 1.23.0 - 1.28.1.

How to fix this

Upgrade the google-adk library to the patch version.