// GeminiHIGH
Pillar Security disclosed an agent-to-agent attack vulnerability in Google's Agent Development Kit (ADK) for Python. A crafted prompt to a low-privilege Gemini ADK agent could be exploited to pass malicious hand-off comments to privileged agents, potentially exposing secrets and enabling pull request tampering.
- Gemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pul(opens in a new tab)
- Gemini agent-to-agent attack exposes secrets and enables pull re(opens in a new tab)
- Google ADK for Python Repo Vulnerability: Agent-to-Agent Privile(opens in a new tab)
// Get alerts for Gemini