Agent-to-Agent Privilege Boundary Failures in Google ADK for Python (adk-python) CI/CD Workflows via Cross-Agent Prompt Injection

Agent-to-Agent Privilege Boundary Failures in Google ADK for (TL-2026-1897), also tracked as Agent-to-Agent Prompt Injection Attack, is a critical-severity software vulnerability, first published 2026-08-05. It has no confirmed attribution, affects Google Agent Development Kit (ADK) for Python, references 1 CVE (CVE-2026-4810), maps to 17 MITRE ATT&CK techniques (T1005, T1036, T1059), and is covered by 9 detection rules and 18 indicators of compromise.

Key facts for TL-2026-1897

Threat ID
TL-2026-1897
Also known as
Agent-to-Agent Prompt Injection Attack, Cross-Agent Privilege Escalation
Severity
CRITICAL
Status
PATCHED
Category
VULNERABILITY
First published
2026-08-05
Last reviewed
2026-08-05
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
technology, software-development, devops, cybersecurity, cloud-computing
Target regions
Global
Detection rules
9
Indicators of compromise
18

Malware and tooling in Agent-to-Agent Privilege Boundary Failures in Google ADK for

Malware and tooling: Python, ADK Agent Development Kit for Python (google-adk), Antigravity SDK, Google Cloud Run / GKE

Pillar Security researchers Dan Lisichkin and Ariel Fogel demonstrated the first practical, real-world case of agent-to-agent exploitation in a production multi-agent system. Prompt injection targeting Google's ADK Python GitHub Actions CI/CD workflows enabled a low-privileged public-facing triage agent to cross privilege boundaries and trigger a high-privileged agent, leading to Remote Code Execution on CI runners, credential exfiltration (adk-bot PAT, GOOGLE_API_KEY, ADK_GCP_SA_KEY), and software supply chain compromise risk. Google remediated by deleting three vulnerable workflows (commit 66730e9). A separate code-injection vulnerability in the distributed google-adk Python package (CVE-2026-4810, CVSS 9.3) was also disclosed during the same window.

How Agent-to-Agent Privilege Boundary Failures in Google ADK for works

In mid-2026, Pillar Security researchers discovered and demonstrated the first practical, real-world case of agent-to-agent exploitation in a production multi-agent system, targeting the google/adk-python GitHub repository (Google's Agent Development Kit for Python). The repository ran two classes of automated AI agents at different privilege levels: low-privilege agents embedded in workflows open to public interaction (triggered when a user opened a pull request or issue) and high-privilege agents meant only for maintainers with real repository authority. The critical design flaw was that the adk-bot agent commented as a human Collaborator account bound to a long-lived Personal Access Token (PAT), giving it elevated trust in the authorization model.

The attack unfolded across two disclosed vectors. Attack Path 1 targeted the PR triage agent (adk_pr_triaging_agent), whose tools were limited to get_pull_request_details, add_label_to_pr, and add_comment_to_pr. An attacker could open a malicious pull request containing a prompt injection disguised as a PR summary. The triage agent, following the injected instructions, would post a comment starting with @gemini-cli, which triggered the maintainer-only gemini-dispatch.yml workflow. Because gemini-invoke.yml lacked a tools.core restriction, the attacker-controlled prompt had access to every bash command on the runner, enabling RCE and exfiltration of the GITHUB_TOKEN (scoped to issues:write and pull-requests:write). From there, the attacker could edit triager comments, submit approving PR reviews as github-actions[bot], dismiss review requests, and remove needs-review labels to fabricate a believable human-audited approval trail.

Attack Path 2 exploited a second wave of automation Google added after the initial disclosure: issue-analyze.yml (ungated, runs automatically on any external issue/PR) and issue-fix.yml (gated to only trigger when a collaborator comments /adk-issue-fix). An attacker prompt-injected a public GitHub issue so that issue-analyze.yml posted /adk-issue-fix as adk-bot, which was a collaborator. Since the authorization gate only checked who posted — not whether an outsider had manipulated the trusted account behind it — issue-fix.yml was triggered with elevated permissions. The Antigravity-SDK-based agent's run_command tool was restricted via _is_safe_command to only allow gh and git commands, but three bypasses existed: (1) git -c core.hooksPath=<dir> to run hook scripts from attacker-controlled directories; (2) git -c 'alias.x=!<cmd>' x to execute shell commands through git aliases; and (3) file-write tools were completely ungated, allowing the agent to write a malicious payload script and invoke it via allowlisted git commands. The fix workflow's environment included ADK_TRIAGE_AGENT (long-lived adk-bot PAT), GOOGLE_API_KEY, and ADK_GCP_SA_KEY (GCP service account key with Vertex AI access on a dedicated project), enabling full credential exfiltration on RCE.

Google confirmed both fixes: attack path 1 was hardened by July 9, 2026, and attack path 2 was fully remediated by July 21, 2026 (commit 66730e9) by deleting three workflow files (issue-analyze.yml, issue-fix.yml, pr-analyze.yml — 334 lines removed, zero additions). The VRP panel declined a financial reward for the first report, citing social-engineering requirements in the full exploit chain, but granted Honorable Mention. Separately, CVE-2026-4810 disclosed a code-injection vulnerability in the distributed google-adk Python package (versions 1.7.0 to 1.28.0, and 2.0.0a1) allowing unauthenticated RCE on the ADK server via malicious YAML configs with args keys uploaded through the builder UI (CWE-306, CVSS 4.0 score 9.3/Critical).

The root cause — compositional security failures where each component was defensible in isolation but risk lived in cross-agent privilege boundaries — represents a new class of attack surface. Pillar Security used their CFS (Critical Failure Surface) Framework to identify the chain. The key architectural lesson is that natural language has effectively joined the authorization path: an agent's authority extends beyond its assigned tools to any privileged system its output can reach, and when one agent's message can satisfy another agent's trigger gate, a privilege-boundary crossing exists that attackers can exploit.

MITRE ATT&CK techniques used in TL-2026-1897

Collection

T1005 Data from Local System

Defense Evasion

T1036 Masquerading; T1574 Hijack Execution Flow

Execution

T1059 Command and Scripting Interpreter; T1203 Exploitation for Client Execution

Command and Control

T1071 Application Layer Protocol

Initial Access

T1078 Valid Accounts; T1190 Exploit Public-Facing Application

Discovery

T1082 System Information Discovery

Persistence

T1098 Account Manipulation

Credential Access

T1528 Steal Application Access Token; T1552 Unsecured Credentials

Privilege Escalation

T1548 Abuse Elevation Control Mechanism

Lateral Movement

T1550 Use Alternate Authentication Material

defense-impairment

T1556 Modify Authentication Process; T1685 Disable or Modify Tools

Impact

T1565 Data Manipulation

Affected products and versions in Agent-to-Agent Privilege Boundary Failures in Google ADK for

  • Google — Agent Development Kit (ADK) for Python
    Vulnerable versions: 1.7.0; 1.28.0
    Fixed in: 1.28.1
  • Google — google/adk-python GitHub repository (CI/CD agent workflows)
    Vulnerable versions: Pre-July-2026 workflows: gemini-invoke.yml, gemini-review.yml, gemini-dispatch.yml, issue-analyze.yml, issue-fix.yml, pr-analyze.yml
    Fixed in: Commit 66730e9 (July 21, 2026) — workflows removed and repository hardened

Remediation for Agent-to-Agent Privilege Boundary Failures in Google ADK for

Patches

  • Upgrade google-adk Python package to >=1.28.1 (stable) or >=2.0.0a2 (alpha) for CVE-2026-4810
  • Apply commit 66730e9 or later to remove or redesign agent workflows processing untrusted issue/PR content
  • Pin CI runner images and apply OS-level security patches for git hooksPath mitigation

Immediate actions

  • Review all CI/CD GitHub Actions workflows for agent-to-agent trust chains where lower-privilege agent output triggers higher-privilege agents
  • Audit bot accounts with Collaborator-level PATs; replace with GitHub Apps with minimum-scoped tokens per workflow
  • Restrict PR/issue-triggered workflows to run only on events from trusted users (not external contributors)

Workarounds

  • Disable community-contributed workflow runs on public repos if agent workflows are enabled
  • Use separate bot identities per trust level — never share a PAT between low-privilege and high-privilege workflows
  • Add explicit tool-scoping to all AI agent workflow steps (deny all tools by default, allow only what's needed)
  • Implement runtime credential rotation per job instead of long-lived PATs
  • Restrict git commands in agent run_command policies (deny -c, --config-env, --exec-path)

Longer-term hardening

  • Implement content-independent authorization signals — don't let agent output satisfy trigger gates designed for human collaborators
  • Treat any low-privilege agent's output as untrusted input to higher-privilege agents; add content-validation gates
  • Map transitive authority chains: trace every path from external untrusted input through every downstream agent and system
  • Audit framework-level agent permission models (ADK, LangChain, MCP, Antigravity SDK) for similar trust assumptions
  • Log changes to reviews, comments, and approval states in an independent system that the workflow's own identity cannot alter

CVEs associated with Agent-to-Agent Privilege Boundary Failures in Google ADK for

CVE-2026-4810

Weaknesses (CWE) in Agent-to-Agent Privilege Boundary Failures in Google ADK for

CWE-306, CWE-94, CWE-74, CWE-285, CWE-284

Timeline of Agent-to-Agent Privilege Boundary Failures in Google ADK for

  • CVE-2026-4810 published — critical code injection vulnerability in google-adk Python packages 1.7.0 through 1.28.0 and 2.0.0a1 allowing unauthenticated RCE via malicious YAML config uploads through the builder UI
  • Dan Lisichkin (Pillar Security) filed first vulnerability report to Google's OSS VRP documenting agent-to-agent prompt injection privilege escalation via gemini-invoke and PR triage workflows
  • Pillar Security submitted video proof-of-concept and detailed attack scenario demonstrating end-to-end exploit chain from prompt injection through PR tampering
  • Second vulnerability report filed by Ariel Fogel (Pillar Security) documenting the Antigravity SDK RCE path via issue-analyze.yml and issue-fix.yml workflows using git hooksPath and git alias command injection
  • Pillar Security shared blog post draft with Google for coordinated disclosure review
  • Google confirmed first-round hardening of ADK repository; VRP panel declined financial reward but granted Honorable Mention, citing social-engineering requirements in the full exploit chain
  • Google confirmed the exposed GCP service account key (ADK_GCP_SA_KEY) had Vertex AI access on a dedicated GitHub-management project
  • Google applied final fix in commit 66730e9 (GWeale, copybara-github): deleted three workflow files — issue-analyze.yml (77 lines), issue-fix.yml (129 lines), pr-analyze.yml (128 lines) — totalling 334 lines removed, zero additions. Rationale: workflows ran automated agents over untrusted issue and PR content with broad repository credentials
  • Pillar Security published full technical disclosure blog post 'I'll Just Call You: Agent-to-Agent Privilege Boundary Failures in CI/CD on Google's ADK Repository'. Coverage by Dark Reading, The Register, InfoWorld, SC Media, and The Cyber Signal
  • The Hacker News and additional outlets published coverage confirming Google deleted three ADK AI workflows (issue-analyze.yml, issue-fix.yml, pr-analyze.yml) from the main branch

Sources cited for Agent-to-Agent Privilege Boundary Failures in Google ADK for

Threats related to Agent-to-Agent Privilege Boundary Failures in Google ADK for

Detection coverage for TL-2026-1897

As of 2026-08-05, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1897 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats