One Permission Turns Google Dialogflow CX Into a Rogue Agent

Key Takeaways

  • Varonis Threat Labs disclosed a permission-boundary flaw in Google Dialogflow CX’s Code Blocks feature.
  • An attacker holding only the dialogflow.playbooks.update permission could inject persistent code into an agent’s pipeline.
  • Because all agents in a GCP project shared one Cloud Run execution environment by default, the injected code reached every agent in the project.
  • The technique could exfiltrate conversations and plant fake reauthentication prompts to harvest user credentials.
  • Google remediated the issue and reported no known customer compromise; the work is a proof of concept.

A Single Permission Was Enough to Go Rogue

Researchers at Varonis Threat Labs showed that Google Dialogflow CX, a widely deployed enterprise chatbot platform, could be turned against its owners. With only the dialogflow.playbooks.update permission, an attacker could inject persistent malicious code into the agent pipeline and, because agents shared a common execution environment, reach every chatbot in the project. Google has fully remediated the flaw.

What We Know

The vulnerability, nicknamed Rogue Agent, was documented by Varonis Threat Labs and reported to Google in November 2025. As Dark Reading detailed, the flaw lived in the Code Blocks feature of Dialogflow CX, the version of Google’s conversational AI platform used to build enterprise virtual agents. Code Blocks let builders attach custom logic, written as code, to a chatbot’s Playbooks. Varonis found that any principal granted the narrow dialogflow.playbooks.update permission could modify those code blocks and inject instructions that persisted in the agent’s runtime. The deeper problem was architectural: by default, all agents within a single Google Cloud project executed in the same shared Cloud Run environment, so code injected through one agent’s Playbook ran in a context shared by every other agent in the project. Google issued an initial fix in April 2026 and fully resolved the issue by June 2026. The research was published and widely reported in mid-July 2026, and Google stated it had no known indication of customer compromise.

What Could Happen

Rogue Agent is a privilege and trust-boundary failure rather than a single memory-safety bug, and its danger comes from what an injected agent can do. Dialogflow CX agents sit in front of real business workflows and often hold access to customer data, backend systems, and authentication flows. As The Hacker News reported, an attacker who injected code through a Playbook could exfiltrate conversation histories, insert fraudulent reauthentication prompts that harvest legitimate user credentials, and run phishing directly inside a trusted corporate chatbot. Because the malicious code persisted in the shared execution environment, it could affect conversations handled by other agents in the same project, widening the blast radius well beyond the one agent the attacker touched. The AI-specific twist is that the platform treated builder-supplied code and the agent’s own logic as equally trusted, so a modest permission became a foothold for autonomous, machine-speed abuse. No exploitation was observed, and the assessment here reflects the exposure that existed before Google closed it rather than confirmed harm.

Why It Matters

Even though Google patched the flaw before any known abuse, Rogue Agent matters because of where Dialogflow CX runs. The platform powers customer-support, financial-services, and healthcare chatbots that routinely handle regulated personal data, payment details, and login credentials, so a flaw that lets attacker code ride inside those agents is unusually consequential. The shared-execution-environment design meant the risk was not confined to a single misconfigured bot but was a property of how projects were built, a systemic pattern rather than a one-off mistake. For enterprises, the incident is a reminder that adopting a hosted conversational AI platform means inheriting the provider’s trust boundaries, including how narrowly scoped a permission like dialogflow.playbooks.update really is. It also underscores that AI agents blur the line between configuration and code: granting someone the ability to edit a Playbook can quietly grant the ability to run code against sensitive data. Those realities carry governance weight under regimes such as the EU AI Act, GDPR, and HIPAA, where accountability for personal data stays with the deploying organization even when the underlying platform is Google’s.

PointGuard AI Perspective

Rogue Agent is the exact failure mode PointGuard AI is built to contain: a trusted agent that can be pushed into untrusted actions. Through AI Security Posture Management, PointGuard AI discovers the AI agents running across an organization’s cloud environments, including hosted platforms like Dialogflow CX, and surfaces over-broad permissions, shared execution boundaries, and configuration drift before they can be abused. Its agent identity and observability layer gives every agent a verifiable identity and records each action and tool call, so persistent code injected into a pipeline shows up as anomalous behavior rather than silent activity. A pre-execution validation step checks each agent action against its authorized intent and policy before it runs, which is what stops an injected instruction from exfiltrating a conversation or issuing a fraudulent reauthentication prompt while legitimate traffic continues. AI-native data-leak prevention inspects prompts, responses, and tool calls for credentials and regulated data, closing the harvesting path the proof of concept relied on. Organizations can also track disclosures like this on the PointGuard AI Security Incident Tracker. As enterprises hand more customer interactions to conversational agents, trustworthy adoption will depend on independent identity, validation, and monitoring around them, not on assuming a single permission is as narrow as it looks.

Incident Scorecard Details

Total AISSI Score: 7.2/10

Criticality = 9, Dialogflow CX runs customer-facing financial and healthcare chatbots that handle regulated PII, payment data, and credentials, AISSI weighting: 25%

Propagation = 8, all agents in a GCP project shared one execution environment, so injected code cascaded across every chatbot in the project, AISSI weighting: 20%

Exploitability = 5, Varonis published a functional proof of concept and technique, but no exploitation was observed and Google had patched the flaw, AISSI weighting: 15%

Supply Chain = 7, the flaw and its fix sat inside a hosted third-party Google platform that customers depend on and cannot inspect, AISSI weighting: 15%

Business Impact = 6, broad and sensitive potential exposure with credible risk of harm, but no confirmed customer compromise at the time of reporting, AISSI weighting: 25%

Sources

Dark Reading – Dialogflow CX ‘Rogue Agent’ Flaw Enabled AI Chatbot Data Theft

The Hacker News – Rogue Agent Flaw Could Have Let Attackers Hijack Google Dialogflow CX Chatbots

Varonis – Rogue Agent: How a Single Code Block Could Hijack Your AI Conversations in Google’s Dialogflow

AI Security Severity Index (AISSI)

0/10

Threat Level

Criticality

9

Propagation

8

Exploitability

5

Supply Chain

7

Business Impact

6

Scoring Methodology

Category

Description

weight

Criticality

Importance and sensitivity of theaffected assets and data.

25%

PROPAGATION

How easily can the issue escalate or spread to other resources.

20%

EXPLOITABILITY

Is the threat actively being exploited or just lab demonstrated.

15%

SUPPLY CHAIN

Did the threat originate with orwas amplified by third-partyvendors.

15%

BUSINESS IMPACT

Operational, financial, andreputational consequences.

25%

Watch Incident Video

Subscribe for updates:

Subscribe

Ready to get started?

Our expert team can assess your needs, show you a live demo, and recommend a solution that will save you time and money.