One Editable Bot Could Hijack the Whole Project

Edit rights on one Dialogflow CX Code Blocks agent were enough to reach the shared runtime behind every agent in the same Google Cloud project. The standard per-bot trust model misses that one writable agent can become project-wide code execution and conversation access. Varonis found that Dialogflow’s Code Blocks run in a shared Google-managed environment, and that the shared runtime file controlling execution was writable. Google fixed the flaw, which affected organizations using Dialogflow Playbooks and custom Code Blocks with dialogflow.playbooks.update rights. The forward risk is broader than one product. Any assistant or workflow system that lets users edit logic in a shared backend can turn content-edit access into execution rights across tenants or agents.

Part of the PlainSec briefing for 2026-07-07

Sources