Security researchers find privilege escalation flaws in Google's Agent Development Kit for Python
Pillar Security discovered multiple attack paths in Google's Agent Development Kit for Python (90+ million downloads) that could allow public-facing AI agents to trigger more privileged automation, manipulate pull-request reviews, and expose credentials through prompt injection in malicious pull requests. The researchers demonstrated the first documented agent-to-agent exploitation method, where one AI agent could compromise another with higher privileges. Google patched the underlying issue but classified it non-rewardable due to social engineering involvement.
Topics
Sources
- Press Read article
- Press Read article
Go deeper
This intelligence is sourced automatically from public sources across the web and synthesised by the Prefactor AI pipeline. Stories are reviewed before publication.