Pillar Security discovered that a public GitHub issue could manipulate a triage agent into triggering a privileged code-fixing agent in Google's ADK repository, leading to arbitrary code execution and credential exfiltration.
Pillar Security discovered that a public GitHub issue could manipulate a triage agent into triggering a privileged code-fixing agent in Google's ADK repository, leading to arbitrary code execution and credential exfiltration.