logo

Critical Vulnerability in GCP Dialogflow Allows Attackers to Inject Malicious Code

ID: f1d2ac75-402a-57ca-bd99-cc0d989494e6

STIX ID: report--f1d2ac75-402a-57ca-bd99-cc0d989494e6

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-07-07

Date Updated: 2026-07-07

Author: Guru Baran

...
...

A Varonis Threat Labs disclosure describes “Rogue Agent,” a critical Dialogflow CX Playbook Code Blocks vulnerability in GCP that allowed an attacker with dialogflow.playbooks.update permission to overwrite a shared code_execution_env.py and execute persistent arbitrary Python across agents in the same project. Exploits could exfiltrate conversations, impersonate agents, and stage phishing, amplified by a VPC Service Controls bypass and Instance Metadata Service credential exposure; Varonis reported it in Nov 2025, Google shipped fixes in April and completed remediation by June 2026 with no known in‑the‑wild exploitation prior to patching.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.