logo

Rogue Agent Flaw Could Have Let Attackers Hijack Google Dialogflow CX Chatbots

ID: 4ccd08c4-d52b-5501-9dd5-68ebc1c45679

STIX ID: report--4ccd08c4-d52b-5501-9dd5-68ebc1c45679

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2026-07-07

Date Updated: 2026-07-18

Author: [email protected] (The Hacker News)

...
...

**Rogue Agent (Dialogflow CX)**: Varonis discovered a critical flaw in Google Dialogflow CX Code Blocks that allowed an attacker with dialogflow.playbooks.update permission to overwrite a shared runtime file (code_execution_env.py) in the managed Cloud Run environment, enabling arbitrary Python execution across all Code Block-enabled agents in the same project; this could let an attacker read live conversations, exfiltrate user data, and make bots send attacker-crafted messages. The environment also permitted unrestricted outbound internet access and access to the Instance Metadata Service, and Cloud Logging did not record the file overwrite; Google fixed the issue in stages between April and June 2026 and reported no evidence of real-world exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.