google-adk is vulnerable to Information Disclosure
41
Medium Risk
Affected versions of this package may log plain-text OAuth credentials and tokens in the BigQuery Agent Analytics plugin, exposing secrets such as client_secret, access_token, refresh_token, id_token, api_key, and passwords. An attacker able to access BigQuery logs, exported telemetry, or downstream log storage could recover these credentials and use them to impersonate users, access protected services, or move laterally across connected systems.
You are affected if you are using a version that falls within the vulnerable range.
google-adk is vulnerable to Information Disclosure in versions 1.23.0 - 1.28.1.
Upgrade the google-adk library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant