google-adk is vulnerable to Incorrect Authorization
93
Critical Risk
The Agent Development Kit can gate sensitive tool calls behind an explicit confirmation step, but the confirmation processor does not verify that the confirmed tool is registered to the executing agent, that the tool actually requires confirmation, or that the confirmation arguments match the original tool call recorded in the session history. Code that can inject or manipulate events in a session can forge a tool confirmation response and continue execution of an unauthorized or tampered tool call. This bypasses the confirmation authorization boundary and lets tool calls run without a legitimate approval. The fix validates tool registration and the confirmation requirement and matches the confirmation against the original function call before allowing execution.
You are affected if you run a version in the vulnerable range and rely on the tool confirmation flow to gate sensitive tool execution, in a deployment where session/event history can be shaped by untrusted or externally influenced input. In that case a forged confirmation response can resume an unauthorized or argument-tampered tool call without a legitimate approval.
google-adk is vulnerable to Incorrect Authorization in versions 1.14.0 - 2.4.0.
Upgrade the google-adk library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant