When One Agent Can Vouch for Another, You Have a Privilege Boundary Made of Text
On September 9, Pillar Security published research showing that CI/CD workflows on Google's own Agent Development Kit for Python repository — the reference framework Google ships for building agentic applications on Gemini — could be steered by a comment on a public GitHub issue into leaking the repo's long-lived credentials. The same day, MITRE assigned the chain CVE-2026-79696, at CVSS 10.0.
The writeup is Pillar's I'll Just Call You: Agent-to-Agent Privilege Boundary Failures in CI/CD on Google's ADK Repository, with same-day coverage from Dark Reading and SC Media. Formal record at CVE Brief and OffSeq Threat Radar.
The formal CVE is bad on its own. The class of attack next to it is worse.
The formal CVE
CVE-2026-79696 is an unauthenticated RCE in adk web, affecting ADK for Python 2.0.0 and earlier than 2.7.0 (fixed in 2.7.0) on OSS, Cloud Run, and GKE where pytest is installed. The vector is a crafted test-session-replay input to a component the docs assume is a developer's own machine but, in observed deployments, is network-reachable. CWE-184. CVSS 10.0.
A CVSS 10 in a framework whose job is running untrusted-model output through tool-calling is a bulletin plus a design conversation.
The class next to the CVE
The part that is not a single CVE is the chain Pillar demonstrated on the adk-python repo's own CI/CD.
Google's adk-python repo uses AI agents to help maintain itself. A triage agent reads PRs and issues and posts comments. An issue-analysis agent reads reports. Some workflows are more privileged: they run commands on the CI runner, call Gemini with the project's API keys, post as adk-bot using a long-lived PAT.
The privilege boundary between the low-privileged triage agent and the high-privileged Gemini workflow was a piece of text. The higher-privileged workflow believed the lower-privileged one because it asked it to.
Pillar demonstrated the full chain. A prompt injection in a public PR or issue made the triage agent post a comment shaped like a trusted command. The downstream workflow read it, treated it as authoritative — it came from a bot inside the repo — and ran it. Weak command checks let injected instructions execute on the runner. The runner had ADK_TRIAGE_AGENT (adk-bot's PAT), GOOGLE_API_KEY, and ADK_GCP_SA_KEY (the adk-python GCP service account key). All three left the runner.
From the attacker's point of view: write an English sentence in a public GitHub comment that reaches the credentials the repo trusts most.
Pillar reported on June 2 and June 5. Google confirmed the fix July 21, deleting three ADK AI workflows outright (per The Hacker News). CVE and writeup came Sept 9.
Why this is the shape of the next year
A pattern across the last month of agent-framework disclosures:
- Deadbugz, the active MCP supply-chain campaign, exploits the same assumption: a downstream trust decision made on what an upstream party said, not what it is. A malicious MCP server behaves for three tool calls, then rewrites its metadata into credential-hunt instructions.
- CoreBreak (Aug 6 at Black Hat, across Amazon Bedrock AgentCore, Google ADK's older CVE-2026-18236, and Vercel's AI SDK) turned on data shaped like a model-generated tool call being trusted as if a model produced it. The model never got a turn.
- Data Became Code (Alon Hertz, Aug 27, elevated by Schneier Sept 4) turned on AI coding agents following
npx <package>directives in a vendor's publicllms.txt, no ownership check on the package name.
Different substrates. What they share: a moment where an agent grants another agent's output the trust status of "signed by the model", purely because the second looks like it came from somewhere that mattered. That moment is the new privilege boundary, and it is currently made of text.
What actually closes the boundary
The layer where the exploit becomes visible in all four cases is the same. Not the review of incoming text — it will pass, because it is written to. It is the moment the process tries to do what the text asked for.
- Cloning a new repository during a triage run that then invokes
curl | bash. - A "text formatting" MCP tool call whose third invocation walks
~/.ssh. - A CI workflow that reads
ADK_GCP_SA_KEYfrom env and makes an outbound call to a host that is not Google. - An
npx <package>from anllms.txtwhose package resolution goes to a domain registered last week.
Those actions have no benign explanation at the OS layer, regardless of what convinced the agent to run them. That is where the boundary still holds: the syscall, not the prompt.
The named-vendor lesson
Google's remediation was not a hardened prompt. Google deleted three workflows. Correct on this substrate — a control made of text cannot be strengthened into infrastructure — but not scalable. Every OSS project using AI agents to help maintain itself has a copy of this pattern. Every enterprise with an agent that comments on tickets and a second agent that acts on the comments has deployed the vulnerable design.
CVE-2026-79696 is a critical bug in a framework a lot of people build on. The chain next to it is a class. Trust decisions inside agent-driven systems have moved off the model and into the plumbing, and the plumbing was not designed to carry them.
Sources
- Pillar Security — I'll Just Call You: Agent-to-Agent Privilege Boundary Failures
- Dark Reading — Flaws in Google APK for Python Unlock Agent-to-Agent Attack
- SC Media — Agent-to-agent privilege escalation in Google's ADK for Python
- The Hacker News — Google Deletes 3 ADK AI Workflows
- CVE Brief — September 9, 2026
- OffSeq Threat Radar — CVE-2026-79696
SPR{K3 is a security research operation that pairs offensive vulnerability research with runtime behavioral defense. Defend is our runtime agent. To talk about a deployment, reach us at support@sprk3.com.