Story perspectives
Google Dialogflow CX “Rogue Agent” Code-Injection Flaw Patched.
7/14/2026
1 of 2
Story summary
- Varonis Threat Labs reported a “Rogue Agent” flaw in Google Cloud Dialogflow CX that was patched in June 2026, with no exploitation observed.
- The vulnerability needed only the dialogflow.playbooks.update permission to inject malicious Python code into a Cloud Run container.
- Injected code could read history, impersonate responses, exfiltrate data, and trigger phishing prompts to steal credentials.
- Varonis advises auditing playbook updates, whitelisting Code Blocks, and monitoring API logs for suspicious activity.
1 / 2
