Skip to content

Agent-to-agent privilege escalation in Google ADK for Python (2026-08) - #33

Merged
MarouaBoud merged 1 commit into
mainfrom
incident/2026-google-adk-agent-privilege-escalation
Sep 20, 2026
Merged

MarouaBoud merged 1 commit into
mainfrom
incident/2026-google-adk-agent-privilege-escalation

Conversation

@MarouaBoud

Copy link
Copy Markdown
Member

Adds 2026-google-adk-agent-privilege-escalation. A crafted GitHub issue could prompt-inject the public, low-privilege triage agent in Google's ADK for Python, whose output then triggered a maintainer-only agent with broad repo and cloud credentials — reaching code execution on the CI runner and exposing its secrets. Google removed three workflows (issue-analyze.yml, issue-fix.yml, pr-analyze.yml). Discovered by Pillar Security.

Classification: prompt-injection/indirect → multi-agent-failure/cascade → unsafe-action/unauthorized-write. Type: hazard. Severity: high. Confidence: confirmed.

Sources: The Hacker News, SC Media, Cloud Security Alliance.

Verification: validate.py (0 failures), check_links.py (sources reachable), apply_mappings.py --check, build_exports.py and build_site.py build clean.

@MarouaBoud MarouaBoud added the needs-review Auto- or human-drafted; awaits maintainer review before merge label Sep 20, 2026
@MarouaBoud
MarouaBoud merged commit 3f923af into main Sep 20, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

needs-review Auto- or human-drafted; awaits maintainer review before merge

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant