@google/adk is vulnerable to Code Injection
70
High Risk
The RunSkillInlineScriptTool in the skills toolset executes script content supplied by the language model inside the configured code executor. Before the fix, execution proceeds automatically with no human confirmation, and the inline-script tool is available whenever the skills toolset is used, so model output influenced by untrusted input can run arbitrary code in the executor's context. Executing model-provided script content is equivalent to arbitrary code execution. The fix makes the inline-script tool opt-in via an allowInlineScripts flag and adds a server-enforced confirmation gate that surfaces the script and language and rejects execution unless explicitly approved.
You are affected if you are using a version that falls within the vulnerable range and you use the skills toolset together with a configured code executor.
@google/adk is vulnerable to Code Injection in versions 1.0.0 - 1.4.0.
Upgrade the @google/adk library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.