gemini-cli - 💡(How to fix) Fix Hardcoded Development Credentials in A2A Server [1 comments, 2 participants]

Official PRs (…)
ON THIS PAGE

Recommended Tools

×6

Utilities matched from this issue’s tags and category — try them while you read without losing context.

GitHub issue graph ai analysis

Paste a GitHub issue URL. We fetch that issue, discover linked issues from bodies/comments/timeline, collect linked pull requests, and produce a structured English report.

The report is written in English Markdown for sharing and archival.

Helpful · Quick feedback

Loading…
GitHub stats
google-gemini/gemini-cli#26816Fetched 2026-05-11 03:27:37
View on GitHub
Comments
1
Participants
2
Timeline
8
Reactions
0
Timeline (top)
labeled ×4added_to_project_v2 ×1commented ×1issue_type_added ×1
RAW_BUFFERClick to expand / collapse

What happened?

The customUserBuilder in packages/a2a-server/src/http/app.ts contains hardcoded credentials ('valid-token' and 'admin:password') that grant authenticated access to the agent.

What did you expect to happen?

Authentication should be handled through a secure, configurable mechanism or integrated with a proper identity provider, never using hardcoded strings.

Client Information

<details> <summary>Client Information</summary>

OS: linux Date: Sunday, May 10, 2026 Gemini CLI: 0.42.0-nightly

</details>

Login information

Automated audit with Gemini CLI.

Anything else we need to know?

File: packages/a2a-server/src/http/app.ts, Lines 95-108. This allows anyone with access to the network port to gain administrative control over the agent by providing these strings.

Severity: Critical Area: area/security

Vote matrix · Quick signals

Works
Did the solution work? Tap to confirm.
Easy Fix
Was it a quick fix?
Time Saver
Did it save you time?
Blocking
Was it severely blocking?
Common Issue
Are others likely hitting this too?
Flaky / Intermittent
Is it intermittent?
Verified / Reproducible
Can you reproduce it reliably?
Loading…

Still need to ship something?

×6

Another batch ranked right after the header list — different links, same matching logic.

Back to top recommendations

TRENDING

gemini-cli - 💡(How to fix) Fix Hardcoded Development Credentials in A2A Server [1 comments, 2 participants]