Google Dialogflow CX 'Rogue Agent': edit rights on one agent could inject code into every Code Block agent in the project
2026-dialogflow-cx-rogue-agent · 2026-07-14
Researchers found that an attacker with edit rights on a single Code Block-enabled Dialogflow CX agent could inject persistent Python into shared Playbook Code Blocks. Because the platform executed code in a common Google-managed Cloud Run environment with a writable execution file and Python exec(), that code could run against other Code Block agents in the same Google Cloud project — a cross-agent compromise.
System
- Framework
- Google Dialogflow CX (Code Block agents on a shared Cloud Run runtime)
- Tools
- dialogflow-cx, cloud-run
- Vendor
- Autonomy
- supervised-autonomous
Classification
- Primary class
- multi-agent-failure
- Chain
- multi-agent-failure/cascade → unsafe-action/unauthorized-write → data-exfiltration/via-tool
- Attack vector
- n-a
- Causation
- entity: human · intentionality: intentional · timing: post-deployment
Trigger
An attacker holding only the dialogflow.playbooks.update permission on one Code Block-enabled agent injected persistent malicious Python into shared Playbook Code Blocks. The platform executed code in a common Google-managed Cloud Run environment where a writable code_execution_env.py and use of Python exec() allowed the injected code to run and affect other agents in the same project.
Root cause
Code Block agents in a project shared one execution environment without isolation, and that environment was writable and used exec(), so code authored for one agent could persist and execute in the context of others — a broken trust boundary between agents that should have been isolated.
Contributing factors
- Multiple agents shared a single Google-managed Cloud Run execution environment.
- A writable code_execution_env.py plus Python exec() permitted arbitrary, persistent code execution.
- Edit rights on one agent were sufficient to reach all Code Block agents in the project.
Detection
Discovered by Varonis and reported through Google's Vulnerability Reward Program in November 2025; disclosed publicly in 2026.
Recovery
Google shipped an initial fix in April 2026 and fully resolved the issue in June 2026 (about seven months from report to resolution). No CVE was assigned and no in-the-wild exploitation was reported.
Prevention
Isolate per-agent code execution (no shared, writable runtime); avoid exec() on attacker-influenceable content; scope edit permissions so one agent cannot affect others; restrict outbound access and metadata-service token reach from agent runtimes.
Blast radius
- Data
- Exploitation could exfiltrate conversation history, manipulate chatbot responses, impersonate agents for phishing, bypass VPC Service Controls via unrestricted outbound access, and obtain Google-managed service-account tokens from the instance metadata service. confidential
- User harm
- A vulnerability disclosed via Google's VRP and patched; no in-the-wild exploitation was reported. none-reported
- Scope
- Code Block agents within the same Google Cloud project
- Reversibility
- reversible
References
- OWASP LLM
- LLM02 LLM06
- OWASP Agentic
- T3 T13
- MITRE ATLAS
- AML.T0024
- Tags
- multi-agent cross-agent code-injection dialogflow shared-runtime
Sources
Cite this incident
Permalink: https://swarmproof.github.io/agent-postmortems/2026-dialogflow-cx-rogue-agent/
@misc{2026-dialogflow-cx-rogue-agent,
title = {Google Dialogflow CX 'Rogue Agent': edit rights on one agent could inject code into every Code Block agent in the project},
year = {2026},
howpublished = {agent-postmortems},
url = {https://swarmproof.github.io/agent-postmortems/2026-dialogflow-cx-rogue-agent/}
}