Skip to content
Agent-to-Agent Exploitation Discovered in Google's ADK for Python

Agent-to-Agent Exploitation Discovered in Google's ADK for Python

First seen 3 Aug 2026, 21:21 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster August 4, 2026 at 20:27 UTC
  • A vulnerability in Google's adk-python allows low-privileged agents to trigger high-privileged ones.
  • Exploitation could lead to unauthorized access to GitHub credentials and manipulation of pull requests.
  • Google has mitigated the vulnerabilities but considers the exploit non-rewardable due to social engineering.

Pillar Security researchers identified a vulnerability in Google's Agent Development Kit for Python (adk-python) that allows a low-privileged AI agent to trigger a high-privileged agent through prompt injection. This exploit could lead to the extraction of sensitive GitHub credentials, including a GITHUB_TOKEN, enabling unauthorized modifications to pull requests. The attack exploits workflows that allow public-facing agents to interact with more privileged automation, exposing a significant risk in CI/CD environments. Google has since mitigated the vulnerabilities but deemed the exploit non-rewardable due to its reliance on social engineering. This incident marks the first practical demonstration of agent-to-agent exploitation in a production environment, highlighting the need for updated threat models. The affected repository has over 90 million downloads, indicating a wide scope of potential impact. Security professionals are urged to reassess their threat models and consider the implications of AI agents in their workflows.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 48d ago How this analysis works

Timeline

2026-08-01
Pillar Security discovers vulnerability
Pillar Security identifies agent-to-agent exploitation in Google's adk-python repository, allowing privilege escalation.
Theregister
2026-08-03
Google acknowledges vulnerabilities
Google confirms the existence of the vulnerabilities in its ADK for Python and begins mitigation efforts.
Csoonline
2026-08-04
Pillar Security publishes detailed report
Pillar Security releases a report detailing the vulnerabilities and potential attack vectors in the adk-python repository.
Pillar Security
2026-08-04
Google mitigates vulnerabilities
Google implements fixes for the identified vulnerabilities in the adk-python repository to prevent exploitation.
Scworld

More articles in this cluster (8)

Following this threat?

Track Google in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed