{"data":[{"id":"865b0b75-98fb-4d8c-a8ee-9b0c8f6c8343","title":"Security threat modeling for emerging AI-agent protocols: A comparative analysis of MCP, A2A, agora, and ANP","summary":"The source is a December 2026 article in the Journal of Information Security and Applications (Volume 103) by Zeynab Anbiaee, Mahdi Rabbani, Mansur Mirani, Gunjan Piya, Igor Opushnyev, Ali Ghorbani and Sajjad Dadkhah. Its title indicates a comparative security threat modeling analysis of the MCP, A2A, agora and ANP AI-agent protocols. The provided text contains only publication metadata, so no findings or methods are available to report.","sourceUrl":"https://www.sciencedirect.com/science/article/pii/S2214212626002759?dgcid=rss_sd_all","publishedAt":"2026-09-29T12:02:44.280Z","severity":"info","cvssSeverity":null,"cvssScore":null,"labels":["security","research"],"issueType":"research","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["MCP","A2A","agora","ANP"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":[],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"patchAvailable":null,"disclosureDate":null,"capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"agent","llmSpecific":false,"classifierConfidence":0.9,"researchCategory":"peer_reviewed","atlasIds":null},{"id":"525fcb4d-7f9d-4801-b060-b2082edd7563","title":"Flaws in Google APK for Python Unlock Agent-to-Agent Attack","summary":"Google has fixed flaws in its APK for Python that allowed an agent-to-agent attack. The issues exploited a trust boundary between two AI agents with different privilege levels, triggering automation that could compromise the supply chain.","sourceUrl":"https://www.darkreading.com/vulnerabilities-threats/flaws-google-apk-python-agent-to-agent-attack","publishedAt":"2026-08-05T18:03:31.000Z","severity":"medium","cvssSeverity":null,"cvssScore":null,"labels":["security","industry"],"issueType":"news","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":["Google"],"affectedVendorsRaw":["Google","Google APK for Python","AI agents with different privilege levels"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"Google has fixed the issues.","attackType":["supply_chain","other"],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"patchAvailable":null,"disclosureDate":"2026-08-05T18:03:31.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"advanced","impactType":["integrity","confidentiality"],"aiComponentTargeted":"agent","llmSpecific":false,"classifierConfidence":0.8,"researchCategory":null,"atlasIds":null},{"id":"10142eac-90d2-4f0f-992d-d31e9bd4ccc8","title":"Gemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request Tampering","summary":"Pillar Security found an agent-to-agent attack method in Google's Agent Development Kit for Python (google/adk-python) that could expose secrets and enable pull request poisoning. A public-facing low-privileged agent could be manipulated into passing a prompt to a high-privileged maintainer agent, which exposed its tools via the MCP server and allowed remote command execution and extraction of its GitHub token. Google addressed the issue through hardening but did not consider it eligible for a bug bounty, and a later remote code execution flaw in the Antigravity-SDK-based agent's automation features was fixed in late July.","sourceUrl":"https://www.securityweek.com/gemini-agent-to-agent-attack-exposed-secrets-enabled-pull-request-tampering/","publishedAt":"2026-08-04T10:54:30.000Z","severity":"medium","cvssSeverity":null,"cvssScore":null,"labels":["security","industry"],"issueType":"news","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":["Google"],"affectedVendorsRaw":["Google Agent Development Kit (ADK)","Gemini","gemini-cli","Antigravity-SDK"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"Google addressed the first issue through hardening and fixed the second weakness in late July. No further mitigation details are given in source.","attackType":["prompt_injection","supply_chain"],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"patchAvailable":null,"disclosureDate":"2026-08-04T10:54:30.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"advanced","impactType":["confidentiality","integrity"],"aiComponentTargeted":"agent","llmSpecific":true,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":null},{"id":"4dccfad7-6500-41d0-9829-338ecf6c46f1","title":"GHSA-vg22-4gmj-prxw: PraisonAI's unauthenticated A2A official example can reach real LLM-driven `eval()` tool execution","summary":"The first-party PraisonAI A2A server example combines three behaviors into a remotely exploitable chain: it exposes an A2A server without `auth_token`, binds to `0.0.0.0`, and registers a `calculate(expression)` tool implemented with Python `eval(expression)`. An unauthenticated client can send a JSON-RPC `message/send` request to `/a2a`, which passes the message to `agent.chat()`, and with a real Gemini model the LLM invoked `calculate`, executing Python in the server process. The advisory says the chain is confirmed for the official example and deployments following the same pattern, and that the full chain is only claimed for versions where the `/a2a` endpoint is present and confirmed.","sourceUrl":"https://github.com/advisories/GHSA-vg22-4gmj-prxw","publishedAt":"2026-05-29T22:31:26.000Z","severity":"critical","cvssSeverity":"critical","cvssScore":null,"labels":["security"],"issueType":"vulnerability","cveId":"CVE-2026-47391","cweIds":null,"affectedPackages":["PraisonAI@<= 4.6.39 (fixed: 4.6.40)"],"affectedVendors":["Google"],"affectedVendorsRaw":["PraisonAI","A2A","Gemini","gemini-2.5-flash-lite"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":["jailbreak","other"],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0.01165,"epssCheckedAt":"2026-10-10T03:00:41.257Z","kevDateAdded":null,"patchAvailable":true,"disclosureDate":"2026-05-29T22:31:26.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality","integrity","availability"],"aiComponentTargeted":"agent","llmSpecific":true,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":["AML.T0051"]}],"meta":{"total":4,"limit":20,"offset":0}}