PILLAR Security identified a vulnerability in Google's Agent Development Kit for Python, enabling an agent-to-agent attack that could expose secrets and manipulate pull requests (PRs). The findings revealed that a low-privileged agent could be exploited to interact with a high-privileged agent, allowing attackers to execute commands and potentially modify PRs as if they were genuine collaborator actions. This manipulation could poison the PR approval process through social engineering.
Google was notified and strengthened security measures but did not assign a bug bounty since the exploit required additional actions from a trustworthy collaborator. A further vulnerability was found that led to remote code execution without maintainer interaction.