Cross-invocation code-execution capability bleed via shared LlmAgent mutation
Los mantenedores suelen responder en 5 días
@surajksharma07 ya está trabajando en esto.
Desde el 21/9/2026.
Evaluación
Este issue todavía no se ha evaluado.
Descripción
Summary
Before commit f8282dafd3bc63476b76af31d1df3abdad6370fa, an invocation-scoped CFC setting could permanently mutate a shared LlmAgent instance.
When one invocation used RunConfig(support_cfc=True), Runner._new_invocation_context() assigned:
cfc_agent.code_executor = BuiltInCodeExecutor()
If the same long-lived Runner / Agent instance was then reused for another session or request with support_cfc=False, the later invocation could still receive the built-in code_execution capability.
This is a cross-invocation capability/policy bleed: a capability enabled for one invocation persisted into a different invocation that explicitly did not request it.
Affected version
- Reproduced on the direct parent of the fix:
43b73e4f - The released
v2.9.1source contains the vulnerable assignment insrc/google/adk/runners.py - Fix: https://github.com/google/adk-python/commit/f8282dafd3bc63476b76af31d1df3abdad6370fa
Minimal reproduction
The reproduction only needs local ADK objects; no Gemini call, Google API, or external service is required.
- Create one
Agentwithcode_executor=None. - Create one
InMemoryRunnerusing that Agent. - Create independent session A and session B.
- Build invocation A with
RunConfig(support_cfc=True). - Run the code-execution request processor for A.
- Build invocation B with
RunConfig(support_cfc=False)using the same Agent. - Run the same request processor for B.
Expected
Invocation B should not receive BuiltInCodeExecutor, because CFC is disabled for B.
Pre-fix behavior
Invocation B still sees the built-in code-execution capability because invocation A mutated persistent shared Agent state.
Root cause
RunConfig.support_cfc is invocation-scoped, while LlmAgent.code_executor is persistent shared object state.
The pre-fix Runner converted an invocation-scoped decision into a permanent mutation of the shared Agent. Later invocations therefore observed a capability they did not request.
Security / isolation impact
This is a capability-isolation failure, not a claim of code execution on the ADK host itself.
The issue is that a request/session configured without the CFC / built-in code-execution capability can receive that capability because a previous invocation using the same shared Agent enabled it.
This matters for long-lived shared Runner/Agent instances, especially where different sessions, users, or policy contexts use different per-invocation capabilities.
Fixed behavior
Commit f8282dafd3bc63476b76af31d1df3abdad6370fa removes the in-place mutation of Runner.agent and resolves BuiltInCodeExecutor dynamically per invocation in _code_execution.py.
Opening this issue for public tracking/documentation of the affected released behavior and the fix.
- Lenguaje dominante
- Python
- Estrellas
- 21.6k
- Forks
- 4k
- Merge medio
- 12 h 6 min
- PR fusionados (30 d)
- 4
Preparar el entorno
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de google/adk-python
-
[A2A] RemoteA2aAgent(use_legacy=False): extension header written to state['http_kwargs'], ignored by a2a-sdk 1.x transportsPosiblemente ocupada @surajksharma07 la tomó hace 3 días. Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 84/100
google/adk-python#7334 · 2 comentarios · 1 asignado ·
Los mantenedores suelen responder en 5 días
-
GoogleOidcVerifier treats string "false" as a verified email claimPosiblemente ocupada @surajksharma07 la tomó hace 3 días. Abiertocore
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
google/adk-python#7289 · 5 comentarios · 1 asignado ·
Los mantenedores suelen responder en 5 días
-
RestApiTool raises uncaught KeyError when a required path param is omittedPosiblemente ocupada @llalitkumarrr la tomó hace 3 días. Abiertorequest clarification tools
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
google/adk-python#7282 · 5 comentarios · 1 asignado ·
Los mantenedores suelen responder en 5 días
-
CredentialsManager should also extract scopes when populating auth schemesPosiblemente ocupada @sanketpatil06 la tomó hace 6 días. Abiertocore needs review
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
google/adk-python#7266 · 2 comentarios · 1 asignado ·
Los mantenedores suelen responder en 5 días
-
OAuth2 Discovery method fails because FastMCP with GoogleProvider (OAuth) returns issuerUrl with trailing slashPosiblemente ocupada @sanketpatil06 la tomó hace 6 días. Abiertomcp
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
google/adk-python#7265 · 4 comentarios · 1 asignado ·
Los mantenedores suelen responder en 5 días
Todos los issues de google/adk-python
Issues similares
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 85/100
mozilla/bedrock#17413 · 1 reacción ·
Los mantenedores suelen responder en 2 días
-
instance instance add
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
searxng/searx-instances#943 · 1 comentario ·
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
Los mantenedores suelen responder en 1 día
-
bug tools
Dificultad 2/5 1-3 horas Aptitud para principiantes 88/100
Los mantenedores suelen responder en 1 día
-
bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 86/100
lance-format/lance#9655 ·
Los mantenedores suelen responder en 2 días