Skip to content

A2A executor returns raw exception details to remote peers #7445

Description

@alibaytok

Describe the bug

When an A2A agent execution fails, the Python executor places the raw exception text into the peer-visible failed-task response. A remote peer that can invoke the endpoint can therefore receive server-side details such as absolute paths, internal hostnames, ports, configuration-key names, or upstream error text.

This is a request/response confidentiality problem: the peer does not need the throwable text to handle a failed task.

Steps to reproduce

  1. Expose an agent via the documented A2A server path.
  2. Cause a normal server-side failure during execution (for example, a missing configured file or an unavailable internal dependency).
  3. Send an ordinary A2A request from a separate client.
  4. Inspect the final failed-task response.

The current failure handling serializes the exception message into the response, rather than returning a fixed safe summary.

Expected behavior

The peer should receive a generic failure message and an opaque error identifier. Full exception details should be retained only in server logs.

Suggested fix

Port the existing ADK Java behavior: generate a short error ID, log the full throwable server-side under that ID, and return only a fixed failure summary plus the ID to the peer. Keep detailed peer-visible errors only as an explicit local-debug opt-in.

Reference implementation: adk-java commit a3df463, which replaces peer-visible exception text with a fixed message and opaque error ID.

Additional context

This is intentionally scoped to the Python A2A executor and does not claim code execution, credential theft, or access-token disclosure. It is a defense-in-depth fix for information exposure across the A2A trust boundary.

Activity

  1. added a commit that references this issue on Oct 7, 2026
    559aa6a
  2. self-assigned this
    on Oct 8, 2026
  3. added theissue type on Oct 8, 2026
  4. added
    a2a[Component] This issue is related a2a support inside ADK.
    on Oct 8, 2026
  5. sanketpatil06 commented on Oct 9, 2026

    @sanketpatil06

    Hi @alibaytok, thanks for the report. On failure, the executor sends str(e) to the peer in the failed-task message. Porting the adk-java approach (opaque error ID, with full details logged server-side) is the right fix.

    This is being addressed in #7446. @sushant-me, thanks for picking it up. The legacy path looks good. However, the new integration path (a2a_agent_executor_impl.py, used with force_new_version or when the client requests the new-integration extension) still returns str(e). Could you apply the same change there, add a test for it, and move the helper block below the imports?

  6. sushant-me commented on Oct 9, 2026

    @sushant-me
    Contributor

    Follow-up pushed in 483ef1c (PR #7446): the new integration path a2a_agent_executor_impl.py now uses the same opaque failure id, the impl test that asserted the disclosure now pins the id instead, two leak tests were added, and the helper block moved below the imports. 89 passed in tests/unittests/a2a/executor/.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

a2a[Component] This issue is related a2a support inside ADK.

Type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions