A critical vulnerability, dubbed "Rogue Agent" by security researchers, in Google’s Dialogflow CX conversational AI platform could have allowed an attacker with edit rights on a single Code Block-enabled agent to compromise all other Code Block-enabled agents within the same Google Cloud project. This sophisticated flaw presented a significant risk, potentially enabling adversaries to intercept live conversations, exfiltrate sensitive user data, and manipulate chatbot responses to deliver attacker-written messages, including malicious requests for password re-entry.
The vulnerability specifically targeted organizations leveraging Dialogflow CX’s Playbooks feature in conjunction with custom Code Blocks, which allow developers to embed their own Python code directly into chatbot conversation flows. While the attack was not a remote, unauthenticated exploit, requiring an initial foothold, its potential for lateral movement across an entire project made it particularly concerning for enterprises relying on Dialogflow CX for critical customer interactions. Google has since patched the flaw, and both Google and the discovering firm, Varonis, have stated there is no evidence of the vulnerability being exploited in the wild.
Understanding Google Dialogflow CX and Its Role in Enterprise AI
Google Dialogflow CX is a robust conversational AI platform designed to enable businesses to build highly sophisticated virtual agents, chatbots, and interactive voice response (IVR) systems. It is part of Google Cloud’s extensive suite of services, offering advanced features for managing complex conversations, integrating with backend systems, and providing a seamless user experience. Enterprises across various sectors, including customer service, e-commerce, banking, and healthcare, adopt Dialogflow CX to automate interactions, improve efficiency, and enhance customer satisfaction. Its appeal lies in its ability to handle intricate conversational flows, leverage natural language understanding (NLU), and integrate custom business logic.
Key to its extensibility are features like Playbooks and Code Blocks. Playbooks allow developers to define structured conversation paths, while Code Blocks provide a powerful mechanism to inject custom Python code directly into these flows. This custom code can perform a variety of functions, such as validating user input, dynamically controlling bot behavior based on external data, invoking external APIs, or integrating with internal enterprise systems. For instance, a Code Block might verify a customer’s account balance, process an order, or retrieve personalized information, making the chatbot experience highly interactive and functional. This capability, while powerful for developers, introduced the vector for the Rogue Agent vulnerability.
The Anatomy of the Rogue Agent Flaw

The core of the Rogue Agent vulnerability lay in the shared runtime environment used by Dialogflow CX’s Code Blocks and a critical oversight in file permissions within that environment. When a developer creates a Code Block, their Python code executes within a Google-managed Cloud Run environment. Crucially, Varonis researchers discovered that all Code Blocks from different agents within the same Google Cloud project shared a single instance of this Cloud Run environment. This lack of isolation between agents, combined with a writable internal file, created the perfect storm for a cross-agent compromise.
Specifically, Varonis identified a file named code_execution_env.py within this shared environment. This file is responsible for wrapping the developer’s custom Python code with internal setup code, defining variables (like history for conversation logs and state for session details) and functions (like respond() to make the bot reply) that the Code Block can access. The critical finding was that this code_execution_env.py file was writable by any Code Block executing within that shared environment.
The attack scenario unfolded as follows:
- Initial Foothold: An attacker, either a malicious insider with legitimate access or an external attacker who has compromised a developer account, gains
dialogflow.playbooks.updatepermission on at least one Code Block-enabled agent. This permission, seemingly innocuous as an "edit" right, proved to be a gateway to code execution. - Malicious Code Block Deployment: The attacker crafts and deploys a malicious Code Block to the compromised agent. This Code Block is designed to perform a specific, covert action.
- Environment Overwrite: The malicious Code Block, leveraging its write access, downloads a modified version of
code_execution_env.pyfrom an attacker-controlled external server. It then overwrites the originalcode_execution_env.pyfile within the shared Cloud Run container. - Persistent Control: From this point forward, every time any Code Block from any agent within that Google Cloud project (that shares the environment) is executed, it runs through the attacker’s modified
code_execution_env.py. This grants the attacker persistent control over the execution flow of all Code Blocks in the project. - Data Exfiltration and Manipulation: The attacker’s injected code, running in the same scope as legitimate Code Blocks, gains access to sensitive conversational data (
history,state), allowing them to read full conversations and exfiltrate user-shared data to their external server. Furthermore, the attacker can use therespond()function to inject attacker-written messages into ongoing conversations, such as phishing prompts requesting users to "re-verify" passwords or sensitive personal information. - Covering Tracks: To maintain stealth, the attacker could then revert the visible Code Block in the Dialogflow console to its original, legitimate state. However, this action only changes what is displayed in the console; the overwritten
code_execution_env.pycontinues to execute in the underlying container, ensuring the attacker’s malicious code remains active and undetectable through superficial checks.
Additional Sandbox Escapes and Security Bypasses
Beyond the primary file overwrite vulnerability, Varonis identified two related issues that further highlighted the inadequate isolation of the Code Block environment:
-
Unrestricted Outbound Internet Access: The Code Block environment was found to have unrestricted outbound internet access. Utilizing the standard Python
urlliblibrary, researchers demonstrated the ability to send data directly to an external server and even receive commands back. This finding was particularly alarming because it meant the environment bypassed Google Cloud’s Virtual Private Cloud (VPC) Service Controls. VPC Service Controls are designed to create security perimeters around sensitive data and services, preventing data exfiltration. The Code Block environment’s ability to reach the open internet effectively turned it into an uncontrolled channel for both data theft and remote command-and-control operations, undermining a fundamental layer of cloud security for enterprises. -
Instance Metadata Service (IMDS) Exposure: The environment also exposed the Instance Metadata Service (IMDS), an internal endpoint that provides metadata about the running instance, including temporary security credentials. While querying the IMDS returned a token for a low-privilege Google-managed service account, the mere accessibility of IMDS from a supposed code-execution sandbox represents a significant security misconfiguration. A well-isolated sandbox should not be able to reach internal cloud infrastructure services like IMDS, regardless of the privilege level of the credentials obtained. This exposure indicated a broader failure in the principle of least privilege and strict environmental isolation.

Detection Challenges and Resolution Timeline
One of the most concerning aspects of the Rogue Agent flaw was the profound lack of visibility for customers. The critical actions of overwriting code_execution_env.py and injecting malicious code occurred entirely within Google’s managed environment, which is opaque to customer-side logging mechanisms. Google Cloud Logging, the primary tool for monitoring activities within a customer’s project, did not record these internal file changes or code injections. This made direct detection of the compromise extremely difficult, if not impossible, for affected organizations from their own telemetry.
Varonis responsibly disclosed the vulnerability to Google through its Vulnerability Reward Program in November 2025. Google acknowledged the flaw and began working on a resolution. An initial fix was deployed in April 2026, with the vulnerability being fully resolved in June 2026. This timeline indicates approximately seven months from the initial report to complete remediation. Notably, no Common Vulnerabilities and Exposures (CVE) identifier was assigned to this flaw, and both Varonis and Google confirmed that there was no indication of the vulnerability having been exploited in real-world attacks.
Broader Implications for AI and Cloud Security
The Rogue Agent vulnerability stands as a stark reminder that the security landscape for artificial intelligence extends far beyond the models themselves. In recent years, much attention has been given to AI-specific flaws like prompt injection, where attackers manipulate a large language model (LLM) through crafted inputs to extract sensitive information or make it perform unintended actions. Varonis’s own "Reprompt" and "SearchLeak" attacks on Microsoft’s Copilot, and Noma Security’s "ForcedLeak" on Salesforce, are prime examples of these model-centric vulnerabilities. Microsoft researchers have even demonstrated how prompt injection can evolve into code execution within AI agent frameworks like Semantic Kernel.
However, Rogue Agent fundamentally differs. It did not exploit a weakness in the Dialogflow CX AI model’s understanding or generation capabilities. Instead, it leveraged a conventional cloud infrastructure flaw: inadequate isolation in a shared runtime environment and a misconfigured file permission. This vulnerability highlights that even as AI models become more sophisticated, the underlying infrastructure, permissions models, and execution environments remain critical attack surfaces.
For enterprises adopting conversational AI, this means a re-evaluation of their security posture. Permissions that appear to be mere "content-edit" rights within an AI development platform must now be understood as potential "code-execution" rights, particularly in shared or multi-tenant environments. The ability to add or modify a Code Block, even for a single agent, can translate into arbitrary Python execution across an entire project if the underlying runtime lacks proper isolation.

This incident also underscores the complexities of the shared responsibility model in cloud computing. While customers are responsible for their data, access controls, and configurations, cloud providers like Google bear the responsibility for the security of the underlying infrastructure, including the isolation of managed services. The fact that customers had no visibility into the internal runtime environment where the compromise occurred emphasizes the need for greater transparency and robust security guarantees from cloud providers regarding their managed AI services.
Recommendations for Organizations Using Dialogflow CX
Given the nature of the Rogue Agent flaw, organizations that deployed Dialogflow CX agents with Code Block Playbooks before the June 2026 fix should take proactive steps to ensure they were not unknowingly targeted. While there is no evidence of exploitation, vigilance remains crucial.
Key recommendations include:
- Permission Audit: Conduct a thorough audit of all roles and accounts that hold the
dialogflow.playbooks.updatepermission within their Google Cloud projects. This is the critical entry point for the attack. Ensure that only trusted personnel with a genuine need have this permission, adhering strictly to the principle of least privilege. - Code Block Review: Scrutinize all Code Blocks deployed during the vulnerable period for any unauthorized or suspicious changes. Look for Code Blocks that might have been modified to download external files or perform unexpected network operations.
- Outbound Connection Monitoring: Monitor outbound network connections from Dialogflow-related services and their associated Cloud Run environments. Look for any unusual or unauthorized communication with external IP addresses or domains that could indicate data exfiltration or command-and-control activity.
- API Call Analysis: Review Google Cloud Audit Logs for any suspicious API calls related to Dialogflow CX, particularly those involving Code Block deployments or modifications by accounts that may have been compromised.
- Implement Strong Access Controls: Beyond immediate audits, reinforce robust access control policies for all developer accounts and service accounts interacting with Dialogflow CX and other AI platforms. Employ multi-factor authentication (MFA) and regular credential rotation.
- Stay Informed: Continuously monitor security advisories and updates from Google and other cloud providers regarding their AI and conversational AI platforms.
In conclusion, the Rogue Agent vulnerability serves as a critical case study in the evolving landscape of cloud-native AI security. It highlights the intricate interplay between developer extensibility features, shared runtime environments, and the potential for lateral movement within cloud projects. As enterprises increasingly embed AI into their core operations, the need for comprehensive security strategies that encompass not only the AI models themselves but also the underlying infrastructure, access controls, and runtime isolation, becomes paramount. Both cloud providers and users must maintain vigilance and adapt their security practices to address these complex, multi-layered threats in the rapidly advancing world of artificial intelligence.
