Google ADK for Python before 2.5.0 allows attackers to forge confirmation events in session history, causing unauthorized execution of sensitive tools. CVSS v4.0 score 9.3. Fixed in ADK 2.5.0.
Google ADK for Python before 2.5.0 allows attackers to forge confirmation events in session history, causing unauthorized execution of sensitive tools. CVSS v4.0 score 9.3. Fixed in ADK 2.5.0.