logo

When AI Agents Go Rogue: Agent Session Smuggling Attack in A2A Systems

ID: 0968428d-f94c-5e88-9892-8e5057556fce

STIX ID: report--0968428d-f94c-5e88-9892-8e5057556fce

Feed Name: Palo Alto Networks Unit 42

Date Published: 2025-10-31

Date Updated: 2026-04-28

Author: Jay Chen and Royce Lu

...
...

This report introduces “agent session smuggling,” a technique that exploits stateful, multi-turn A2A agent communications to inject hidden instructions, enabling context poisoning, data exfiltration, and unauthorized tool execution. Through two proof-of-concept scenarios involving a financial assistant and a malicious research agent, it shows how sensitive data can be leaked and unauthorized trades executed without user visibility, contrasts A2A with MCP’s generally stateless model, and recommends layered mitigations including human-in-the-loop approvals, context grounding, cryptographic agent identity verification, and exposing agent activity to users, alongside relevant Palo Alto Networks protections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.