Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent
The Hacker News
Read full postGoogle removed three AI agent workflows from its Agent Development Kit Python repository after security researchers revealed a vulnerability that allowed a public GitHub issue to manipulate a triage agent into triggering a privileged code-fixing agent, risking arbitrary code execution and credential exposure. The flaw involved a trusted bot identity bypassing authorization checks, though no in-the-wild exploitation has been reported.



