Skip to content

Security audit report (bc-ae777d66) — report only - #9

Draft
cursor[bot] wants to merge 1 commit into
mainfrom
security-audit/bc-ae777d66-11e6-4811-81e1-b570226676bd
Draft

Security audit report (bc-ae777d66) — report only#9
cursor[bot] wants to merge 1 commit into
mainfrom
security-audit/bc-ae777d66-11e6-4811-81e1-b570226676bd

Conversation

@cursor

@cursor cursor Bot commented Aug 1, 2026

Copy link
Copy Markdown

Security Audit Report (Report Only)

This PR contains audit reports only — no remediation code changes.

  • Repository: https://github.com/forked-oss/adk-java
  • Audited revision: ec93f50f10125f5a3728d372e16be4530f12553f
  • Target freshness: fresh (matches origin/main)
  • Run ID: bc-ae777d66-11e6-4811-81e1-b570226676bd

Confirmed findings by severity

  • Critical: 0
  • High: 3
  • Medium: 0
  • Low: 0
  • Informational: 0
  • Unresolved leads: 5

Report locations

  • security-audit/bc-ae777d66-11e6-4811-81e1-b570226676bd/REPORT.md
  • security-audit/bc-ae777d66-11e6-4811-81e1-b570226676bd/findings/

Important limitations

No CodeQL/Semgrep or dependency scanner. No dynamic PoC. CallerStateGuard not present in Java SDK.

Highest-priority findings

  • [High] Path traversal in LocalSkillSource skill resource loading
  • [High] Cross-session state injection via unauthenticated dev web API
  • [High] Unauthenticated ADK dev web server exposes agent execution API
Open in Web View Automation 

…70226676bd

Co-authored-by: quan.m.le <quan.m.le@opswat.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant