Google ADK Python repository workflow prompt-injection security flaw
Vulnerability
Summary
Hide ▲
Show ▼
Google's ADK Python repository workflows had a prompt-injection flaw that let a public GitHub issue steer a trusted triage bot into a privileged code-fixing path. Researchers showed the chain could reach the CI runner, execute arbitrary code, and expose the bot PAT and cloud credentials. Google removed issue-analyze.yml, issue-fix.yml, and pr-analyze.yml after the proof of concept; the record does not show in-the-wild exploitation.
Related Happenings
Google Dialogflow CX Code Blocks shared-runtime isolation security flaw
Vulnerability
H score32
First: 07.07.2026 19:37
Last: 07.07.2026 19:37
Sources 1
About this happening:
Google Dialogflow CX Code Blocks had a shared-runtime isolation flaw that could let one editable agent affect other Code Block-enabled agents in the same Google Cloud pr...
Google Dialogflow CX Code Blocks shared-runtime isolation security flaw
VulnerabilityAbout this happening: Google Dialogflow CX Code Blocks had a shared-runtime isolation flaw that could let one editable agent affect other Code Block-enabled agents in the same Google Cloud pr...
CI/CD pull-request privilege-escalation flaw (Cordyceps)
Vulnerability
H score32
First: 24.06.2026 15:48
Last: 24.06.2026 15:48
Sources 1
About this happening:
Cordyceps exposed a CI/CD workflow privilege-escalation flaw in pull-request automation that let unauthenticated users hijack privileged workflows and reach open-s...
CI/CD pull-request privilege-escalation flaw (Cordyceps)
VulnerabilityAbout this happening: Cordyceps exposed a CI/CD workflow privilege-escalation flaw in pull-request automation that let unauthenticated users hijack privileged workflows and reach open-s...
Shai-Hulud worm clone activity on NPM
Malware Activity
H score69
First: 18.05.2026 12:45
Last: 18.05.2026 12:45
Sources 1
About this happening:
The Shai-Hulud malware activity has continued to evolve across the npm supply chain and related developer ecosystems. It first infected npm packages in September 202...
Shai-Hulud worm clone activity on NPM
Malware ActivityAbout this happening: The Shai-Hulud malware activity has continued to evolve across the npm supply chain and related developer ecosystems. It first infected npm packages in September 202...
Google Antigravity critical prompt-injection RCE flaw
Vulnerability
H score28
First: 21.04.2026 13:52
Last: 21.04.2026 13:52
Sources 1
About this happening:
Google fixed a critical Antigravity flaw that let a prompt injection bypass Secure Mode and escalate to sandbox escape and remote code execution (RCE). The...
Google Antigravity critical prompt-injection RCE flaw
VulnerabilityAbout this happening: Google fixed a critical Antigravity flaw that let a prompt injection bypass Secure Mode and escalate to sandbox escape and remote code execution (RCE). The...
Langflow missing-authentication code-injection flaw (CVE-2026-33017)
Vulnerability
H score55
First: 20.03.2026 17:15
Last: 20.03.2026 17:15
Sources 1
About this happening:
Langflow's CVE-2026-33017 is being actively exploited to deliver a Monero miner through exposed AI application endpoints. The campaign uses unauthenticated R...
Langflow missing-authentication code-injection flaw (CVE-2026-33017)
VulnerabilityAbout this happening: Langflow's CVE-2026-33017 is being actively exploited to deliver a Monero miner through exposed AI application endpoints. The campaign uses unauthenticated R...
Timeline
-
04.08.2026 14:16 1 articles · 2h ago
Bot-generated ADK pull request shows the repository automation was active
Technical Analysis UpdateA bot-generated pull request on June 4, 2026 showed the ADK repository automation was active and able to create an adk-bot pull request.
Show sources
- Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent — thehackernews.com — 04.08.2026 14:16
-
04.08.2026 14:16 2 articles · 2h ago
Google removes three ADK workflow files from the repository
Mitigation Patch UpdateGoogle removed issue-analyze.yml, issue-fix.yml, and pr-analyze.yml from the Agent Development Kit (ADK) Python repository after the workflows processed untrusted issue and pull-request content with broad repository credentials.
Show sources
- Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent — thehackernews.com — 04.08.2026 14:16
- Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent — thehackernews.com — 04.08.2026 14:16
-
04.08.2026 14:16 1 articles · 2h ago
Pillar Security verifies the ADK workflows are absent
Mitigation Patch UpdatePillar Security verified on July 2, 2026 that the three workflow files were absent from the repository, indicating the removal had taken effect.
Show sources
- Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent — thehackernews.com — 04.08.2026 14:16
-
04.08.2026 14:16 1 articles · 2h ago
Google confirms the ADK workflow issue is fixed
Mitigation Patch UpdateGoogle confirmed on July 21, 2026 that the workflow issue had been fixed after the repository changes and subsequent verification.
Show sources
- Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent — thehackernews.com — 04.08.2026 14:16
-
04.08.2026 14:16 1 articles · 2h ago
Public GitHub issue can prompt-inject a privileged ADK code-fixing agent
Initial DisclosurePillar Security disclosed that a public GitHub issue could prompt-inject a triage agent into triggering a privileged code-fixing agent, enabling arbitrary code execution on the CI runner and exposure of the bot personal access token, Google API key, and Google Cloud service-account credential.
Show sources
- Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent — thehackernews.com — 04.08.2026 14:16