Agents
Agent Name Collision: six of seven open-source A2A integrations dispatch to an attacker's peer that copies a trusted agent's name
arXiv 2609.27624 (23 Sept) notes that A2A treats an Agent Card's name as human-readable metadata with no collision semantics, yet hosts use it as a local routing key. In regression tests at seven pinned open-source revisions, six client-style integrations sent requests meant for a trusted peer to an attacker-controlled endpoint. A brokered implementation merged both peers onto one route. The authors found no direct credential or tool transfer in the tested bindings, so the harm is wrong-peer dispatch. If you register remote A2A agents, key them on a verified identity, not the card name.
Source
↳ Follow the thread