importantSYS.SOURCE: The Hacker News• 2026-08-04T16:46:23+05:30
Google Removes Three ADK AI Workflows Due to Privileged Agent Exploit via GitHub
Google removed three AI workflows from its ADK repository after researchers demonstrated a vulnerability allowing privilege escalation through a malicious GitHub issue. The exploit enabled arbitrary code execution and credential exfiltration via compromised CI/CD workflows.
Google deleted three AI agent workflows from its Agent Development Kit (ADK) Python repository. Pillar Security showed that a public GitHub issue could manipulate a triage agent into triggering a privileged code-fixing agent.
The researchers said the public agent could be prompt-injected into posting /adk-issue-fix as adk-bot. They identified the bot as a collaborator, so that comment satisfied
*** END OF TRANSMISSION ***