www.pillar.security Agent-to-Agent Exploitation Discovered in Google's ADK for Python
Article Content
- •A vulnerability in Google's adk-python allows low-privileged agents to trigger high-privileged ones.
- •Exploitation could lead to unauthorized access to GitHub credentials and manipulation of pull requests.
- •Google has mitigated the vulnerabilities but considers the exploit non-rewardable due to social engineering.
Pillar Security researchers identified a vulnerability in Google's Agent Development Kit for Python (adk-python) that allows a low-privileged AI agent to trigger a high-privileged agent through prompt injection. This exploit could lead to the extraction of sensitive GitHub credentials, including a GITHUB_TOKEN, enabling unauthorized modifications to pull requests. The attack exploits workflows that allow public-facing agents to interact with more privileged automation, exposing a significant risk in CI/CD environments. Google has since mitigated the vulnerabilities but deemed the exploit non-rewardable due to its reliance on social engineering. This incident marks the first practical demonstration of agent-to-agent exploitation in a production environment, highlighting the need for updated threat models. The affected repository has over 90 million downloads, indicating a wide scope of potential impact. Security professionals are urged to reassess their threat models and consider the implications of AI agents in their workflows.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (8)
Following this threat?
Track Google in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…