Title: Server-Side Indirect Prompt Injection leading to Rogue Agent Actions in Google AI Studio
Product / Tier: Google AI Studio (Standard Tier)
Vulnerability Category: AI VRP - Rogue Actions / Remote Code Execution via Third-Party Data Injection
Description:
An attacker-controlled external server or repository delivered a malicious payload disguised as developer data or log content. When parsed by an agent connected via Google AI Studio, the system treated the injected instruction as a server-side command override. This allowed a fake developer profile or external source to trigger unauthorized system instructions (Agentjacking) directly within the agent workspace.
Steps to Reproduce:
- Connect an active project session in Google AI Studio to an external data stream, server log feed, or repo issue tracker.
- Ingest a malicious payload from an unauthenticated server endpoint containing hidden system markdown instructions.
- Observe Google AI Studio evaluating the raw payload and executing the untrusted instructions.
Impact:
Allows external threat actors to achieve indirect prompt injection, resulting in unauthorized environment modification or local resource access via the integrated agent runtime.
I’ve had 3 or 4 apps be stolen from same hack