agent-postmortems a structured database of real AI-agent failures

← all incidents

hazard high confidence: confirmed status: final

Google Dialogflow CX 'Rogue Agent': edit rights on one agent could inject code into every Code Block agent in the project

2026-dialogflow-cx-rogue-agent · 2026-07-14

Researchers found that an attacker with edit rights on a single Code Block-enabled Dialogflow CX agent could inject persistent Python into shared Playbook Code Blocks. Because the platform executed code in a common Google-managed Cloud Run environment with a writable execution file and Python exec(), that code could run against other Code Block agents in the same Google Cloud project — a cross-agent compromise.

System

Framework
Google Dialogflow CX (Code Block agents on a shared Cloud Run runtime)
Tools
dialogflow-cx, cloud-run
Vendor
Google
Autonomy
supervised-autonomous

Classification

Primary class
multi-agent-failure
Chain
multi-agent-failure/cascade → unsafe-action/unauthorized-write → data-exfiltration/via-tool
Attack vector
n-a
Causation
entity: human · intentionality: intentional · timing: post-deployment

Trigger

An attacker holding only the dialogflow.playbooks.update permission on one Code Block-enabled agent injected persistent malicious Python into shared Playbook Code Blocks. The platform executed code in a common Google-managed Cloud Run environment where a writable code_execution_env.py and use of Python exec() allowed the injected code to run and affect other agents in the same project.

Root cause

Code Block agents in a project shared one execution environment without isolation, and that environment was writable and used exec(), so code authored for one agent could persist and execute in the context of others — a broken trust boundary between agents that should have been isolated.

Contributing factors

  • Multiple agents shared a single Google-managed Cloud Run execution environment.
  • A writable code_execution_env.py plus Python exec() permitted arbitrary, persistent code execution.
  • Edit rights on one agent were sufficient to reach all Code Block agents in the project.

Detection

Discovered by Varonis and reported through Google's Vulnerability Reward Program in November 2025; disclosed publicly in 2026.

Recovery

Google shipped an initial fix in April 2026 and fully resolved the issue in June 2026 (about seven months from report to resolution). No CVE was assigned and no in-the-wild exploitation was reported.

Prevention

Isolate per-agent code execution (no shared, writable runtime); avoid exec() on attacker-influenceable content; scope edit permissions so one agent cannot affect others; restrict outbound access and metadata-service token reach from agent runtimes.

Blast radius

Data
Exploitation could exfiltrate conversation history, manipulate chatbot responses, impersonate agents for phishing, bypass VPC Service Controls via unrestricted outbound access, and obtain Google-managed service-account tokens from the instance metadata service. confidential
User harm
A vulnerability disclosed via Google's VRP and patched; no in-the-wild exploitation was reported. none-reported
Scope
Code Block agents within the same Google Cloud project
Reversibility
reversible

References

OWASP LLM
LLM02 LLM06
MITRE ATLAS
AML.T0024
Tags
multi-agent cross-agent code-injection dialogflow shared-runtime

Sources

Cite this incident

@misc{2026-dialogflow-cx-rogue-agent,
  title = {Google Dialogflow CX 'Rogue Agent': edit rights on one agent could inject code into every Code Block agent in the project},
  year = {2026},
  howpublished = {agent-postmortems},
  url = {https://swarmproof.github.io/agent-postmortems/2026-dialogflow-cx-rogue-agent/}
}