Rogue Agent Flaw Could Have Let Attackers Hijack Google Dialogflow CX Chatbots
ID: 4ccd08c4-d52b-5501-9dd5-68ebc1c45679
STIX ID: report--4ccd08c4-d52b-5501-9dd5-68ebc1c45679
Feed Name: The Hacker News
**Rogue Agent (Dialogflow CX)**: Varonis discovered a critical flaw in Google Dialogflow CX Code Blocks that allowed an attacker with dialogflow.playbooks.update permission to overwrite a shared runtime file (code_execution_env.py) in the managed Cloud Run environment, enabling arbitrary Python execution across all Code Block-enabled agents in the same project; this could let an attacker read live conversations, exfiltrate user data, and make bots send attacker-crafted messages. The environment also permitted unrestricted outbound internet access and access to the Instance Metadata Service, and Cloud Logging did not record the file overwrite; Google fixed the issue in stages between April and June 2026 and reported no evidence of real-world exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
