Repository navigation
Quote user_id literals in VertexAiSessionService list filters #5270
Description
Activity
- addedservices[Component] This issue is related to runtime services, e.g. sessions, memory, artifacts, etc[Component] This issue is related to runtime services, e.g. sessions, memory, artifacts, etc
on Apr 10, 2026 @petrmarinec Thanks for the clear write-up — reproduced the injection on our end against the config['filter'] line in list_sessions()!
A workaround worth verifying: escape backslashes first, then double-quotes in user_id before interpolation (value.replace("\", "\\").replace('"', '\"')).
That keeps the whole value inside the AIP-160 string literal regardless of what's passed in.Since you already have PR #5273 in flight, could you confirm that approach handles edge cases like backslash-only input and empty strings on your side before pushing it to review?
Thanks, confirmed and pushed an update to #5273.
I changed the helper to use the escaping order you suggested: escape backslashes first, then double-quotes before wrapping the value in quotes.
Added regression coverage for these cases:
attacker" OR user_id!=""->user_id="attacker\" OR user_id!=\"\""\->user_id="\\"- empty string ->
user_id=""
Verified locally:
PYTHONPATH=src python -m pytest tests/unittests/sessions/test_vertex_ai_session_service.py- Result:
31 passed
@petrmarinec That's exactly the coverage we needed — quote injection, backslash-only, and empty string nail the full edge-case surface for AIP-160 literal escaping, and 31/31 passing looks solid!
Team is looking more into it.
- addedneeds review[Status] The PR/issue is awaiting review from the maintainer[Status] The PR/issue is awaiting review from the maintainer
on Apr 19, 2026 @DeanChensj Please have a look into it once.
Thanks for the PR!
Reacted by yyy- added a commit that references this issue
on Apr 22, 2026 @petrmarinec The fix from PR #5273 has been merged — _quote_filter_literal() is now live in vertex_ai_session_service.py and the config['filter'] line uses it correctly.
The injection is no longer possible in v1.30.0 and later.
Thanks again for the thorough write-up, the edge-case test coverage, and the clean PR.
- added a commit that references this issue
on Jul 20, 2026 - added a commit that references this issue
on Aug 11, 2026 - added a commit that references this issue
on Aug 30, 2026 - added a commit that references this issue
on Sep 29, 2026 - added a commit that references this issue
on Sep 29, 2026
Summary
VertexAiSessionService.list_sessions()builds an AIP-160 filter by interpolating rawuser_idinto a quoted literal. Embedded quotes can break out of that literal and append extra filter syntax.Affected code
src/google/adk/sessions/vertex_ai_session_service.pyProblem
The current code builds:
user_id="{user_id}"So a value such as
attacker" OR user_id!=""produces:user_id="attacker" OR user_id!=""That changes the filter expression instead of keeping the whole value inside the string literal.
Expected behavior
user_idshould be quoted as a filter literal before interpolation so embedded quotes and backslashes stay inside the value.Proposed fix
Quote the filter literal before constructing the AIP-160 filter string and add a regression test that captures the exact filter passed to the Vertex client.
Validation
I have a PR prepared that:
user_idbefore building the filterorigin/mainpytest tests/unittests/sessionsin clean Linux Docker