Critical Vulnerability in GCP Dialogflow Allows Attackers to Inject Malicious Code
ID: f1d2ac75-402a-57ca-bd99-cc0d989494e6
STIX ID: report--f1d2ac75-402a-57ca-bd99-cc0d989494e6
Feed Name: cybersecurityNews.com
A Varonis Threat Labs disclosure describes “Rogue Agent,” a critical Dialogflow CX Playbook Code Blocks vulnerability in GCP that allowed an attacker with dialogflow.playbooks.update permission to overwrite a shared code_execution_env.py and execute persistent arbitrary Python across agents in the same project. Exploits could exfiltrate conversations, impersonate agents, and stage phishing, amplified by a VPC Service Controls bypass and Instance Metadata Service credential exposure; Varonis reported it in Nov 2025, Google shipped fixes in April and completed remediation by June 2026 with no known in‑the‑wild exploitation prior to patching.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
