@google/adk is vulnerable to Missing Authentication
75
High Risk
The toA2a utility mounts an Agent-to-Agent server that exposes an agent and its tools over REST and JSON-RPC. Before the fix, both handlers default to no authentication, so a mounted A2A server is reachable by any network caller without credentials. This lets unauthenticated callers invoke the agent and its tools. The fix makes toA2a fail closed by requiring an explicit authentication user builder, and only permits unauthenticated access when allowUnauthenticated is deliberately set for local development.
You are affected if you are using a version that falls within the vulnerable range and you mount an Agent-to-Agent server with toA2a without configuring authentication.
@google/adk is vulnerable to Missing Authentication in versions 0.6.0 - 1.4.0.
Upgrade the @google/adk library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.