Google ADK for Python: A Chain of Vulnerabilities Enables Attacks Between AI Agents

Discover how a chain of vulnerabilities in Google ADK for Python enables attacks between AI agents, affecting GitHub and CI/CD pipelines.

Google ADK for Python: A Chain of Vulnerabilities Enables Attacks Between AI Agents
Vulnerabilities

Illustrative image generated with AI

GitHub prompt injection targeting agents with different privilege levels

Pillar Security identified a chain of vulnerabilities in Google’s Agent Development Kit (ADK) for Python, distributed through the adk-python repository.

The attack begins with a pull request or GitHub issue containing manipulated instructions. A public agent with limited privileges can use them to influence an internal agent responsible for maintenance.

The second agent, equipped with broader permissions, can then be tricked into performing unauthorized operations. The underlying issue is therefore not limited to the contents of a single prompt injection, but also involves automated delegation between agents with different levels of trust.

The risk to Gemini, GitHub, and CI/CD pipelines

The vulnerability affects scenarios that combine ADK with Gemini, Gemini CLI, GitHub workflows, and CI/CD automation. The package has surpassed 90 million downloads.

In an exposed environment, the chain could facilitate:

  • indirect privilege escalation between agents;
  • approval or publication of unauthorized changes;
  • execution of malicious code in pipelines;
  • software supply chain compromise.

A public agent does not necessarily need to obtain administrative privileges directly: it can use the internal agent as an operational intermediary.

Pillar Security reported the flaws to Google in early June. The research was made public on August 4. The source does not provide a CVSS score or CVE identifiers.

Fixes and safeguards for ADK environments

Google fixed the vulnerabilities on July 9 and July 21. ADK users should update the package to the patched versions and also review the dependencies used by their projects.

The main countermeasures include:

  • strictly isolating public agents from privileged agents;
  • preventing untrusted inputs from generating operational commands;
  • requiring manual approval before triggering sensitive workflows;
  • monitoring and validating GitHub events;
  • applying the principle of least privilege to CI/CD pipelines.

Role separation must be accompanied by controls over delegated actions: a privileged agent should not automatically treat instructions originating from public content as trusted.

Read next

Sources

This article is an original reworking based on the sources below.

Back to home

Latest Cybersecurity News

All cybersecurity news →