Vulnerabilities · 68 days ago
Edit rights on one Dialogflow CX Code Blocks agent were enough to reach the shared runtime behind every agent in the same Google Cloud project. The standard per-bot trust model misses that one writable agent can become project-wide code execution and conversation access.
Varonis found that Dialogflow’s Code Blocks run in a shared Google-managed environment, and that the shared runtime file controlling execution was writable. Google fixed the flaw, which affected organizations using Dialogflow Playbooks and custom Code Blocks with dialogflow.playbooks.update rights.
The forward risk is broader than one product. Any assistant or workflow system that lets users edit logic in a shared backend can turn content-edit access into execution rights across tenants or agents.
3 sources covering this story
Google Dialogflow CX Bug Allowed Attackers to Hijack AI Conversations
The
Dialogflow CX 'Rogue Agent' Flaw Enabled AI Chatbot Data Theft
Varonis reported the flaw to Google in late 2025 and it has been addressed, but it reminds defenders to take a look at their AI Infrastructure security.
Rogue Agent Flaw Could Have Let Attackers Hijack Google Dialogflow CX Chatbots
Google fixed Rogue Agent, a Dialogflow CX Code Blocks flaw that could let one writable agent affect every chatbot in a Cloud project.
Part of the PlainSec briefing for 2026-07-07