He would have to attach it "below" the merchant's tx, but yes, you're right, it's a possible attack vector. Anyhow, the referencing algorithm is not yet finished, so we are discussing it with CfB right now.
Possible? I don't see how it's possible to draw a picture to have longest-path-as-the-score rule to be broken by an adversary.
Remember that the "longest path algo" is not what's written in the whitepaper

Anyhow, let's finish our private discussion in slack and only then make the results public.