Rogue Agent Flaw Could Have Let Attackers Hijack Google Dialogflow CX Chatbots 13%

By Swati Khandelwal11%

7/7/2026, 5:02:12 PM

BS Summary: This article contains 22 faulty reasoning types, including Indoctrination, Appeal to Authority, and False Dilemma, with Negativity Bias as the most egregious example at 16% saturation with 157 hits. Analysis detected 1,068 faulty-reasoning hits from 980 analyzed words, generating a BS Score of 29.5% and a BS Rank of 13% (19,146 of 21,886 articles). This article is better (less manipulative) than 87.50% of the article peer group.

A critical flaw in Google's Dialogflow CX could have let an attacker with edit rights on one Code Block-enabled agent compromise other Code Block-enabled agents in the same Google Cloud project. 
From there, they could read live conversations, steal the data users shared, and make the bots send attacker-written messages, including requests to re-enter a password. 
Security firm Varonis found it and named it Rogue Agent. 
The flaw affected only organizations that built agents with Dialogflow's Playbooks and custom Code Blocks, which let developers add their own Python. 
And it was not a remote, unauthenticated attack. 
Pulling it off needed the dialogflow.playbooks.update permission on one such agent, which limits the realistic attacker to a malicious insider or a compromised developer account, not a stranger on the internet. 
From that one foothold, though, the reach extended to every agent in the project. 
Google has fixed it, and both Varonis and Google say there is no sign the flaw was ever used in a real attack. 
One writable file ran every agent's Code Blocks 
Dialogflow's Code Blocks let developers add custom Python to a chatbot’s conversation flow to check input, control behavior, and invoke defined tools. 
That code runs in a Google-managed Cloud Run environment, and every agent that uses Code Blocks in the same Google Cloud project shares one instance of it. 
Google runs that environment, the customer cannot see or control it, and Varonis found no real isolation between the agents inside it. 
When an agent runs a Code Block, the developer's code is appended to internal setup code and passed to Python's exec() function. 
That setup code defines the variables and functions the block can touch. 
Variables include history for the full conversation and state for session details like the session ID. 
Functions include respond(), which makes the bot reply with a given string. 
Varonis found the file that does this wrapping, code_execution_env.py, sitting in the shared environment with write access. 
Because that file was writable, a single Code Block could replace it. 
That block downloads a modified code_execution_env.py from an attacker-controlled server and overwrites the original inside the running container. 
From then on, the attacker's version runs for every Code Block execution across every agent sharing that environment. 
It sits in the same scope as legitimate code, with the same access to history, state, and respond(). 
That lets it read each conversation, quietly send it to the attacker's server, and make the bot post attacker-written messages. 
One example is phishing: the bot asks the user to re-verify a login, and the attacker collects whatever they type. 
To cover the tracks, the attacker restores the original Code Block in the Dialogflow console. 
That changes only what the console displays; the overwritten file is already running in the container and keeps executing underneath. 
The sandbox leaked two more ways 
Varonis reported two related issues, and neither needed the file overwrite. 
First, the Code Block environment had unrestricted outbound internet access. 
Using the built-in urllib library, the researchers sent data straight to an external server and could receive commands back. 
Varonis says this bypasses VPC Service Controls, the Google Cloud perimeter meant to stop data from leaving protected services. 
The environment sits outside that perimeter and can reach the open internet, which turns it into a channel for both data theft and remote control. 
Second, and less serious, the environment exposed the Instance Metadata Service (IMDS), a normally internal endpoint that hands out cloud credentials. 
Querying it returned a token for a Google-managed service account. 
That account was low-privilege, so the direct risk was limited; the real point is that a code-execution sandbox should not be able to reach IMDS at all. 
Almost nothing reached the logs 
The overwrite happened inside Google's environment, where customers have no visibility, and Cloud Logging did not record the file change or the injected code. 
That makes it hard, though not impossible, to catch from the customer side. 
The setup actions still leave traces, which the checks below rely on. 
Varonis disclosed the flaw through Google's Vulnerability Reward Program in November 2025. 
Google shipped an initial fix in April 2026 and fully resolved it in June 2026, about seven months from report to resolution. 
No CVE was assigned. 
What to check if you used Code Blocks 
If you ran Dialogflow CX agents with Code Block Playbooks before the fix and want to confirm you were not targeted, start with access. 
The dialogflow.playbooks.update permission is the whole entry point, so audit which roles and accounts hold it. 
Then: 
Review your DATA_WRITE audit logs for the Dialogflow API for unexpected playbook updates, and correlate them with unusual users, IP addresses, or access times. 
Run a Cloud Logging query for failed user requests, where the error messages can reveal exceptions thrown by malicious Code Blocks. 
In the Dialogflow console, open Playbooks for each agent and confirm every Code Block is one you approved. 
A different kind of AI flaw 
Many recent AI security flaws have worked by fooling the model. 
Varonis's own Reprompt and SearchLeak turned a single click into data theft in Microsoft's Copilot. 
Noma Security's ForcedLeak hid instructions in a Salesforce web form to pull out CRM data. 
Microsoft's researchers showed prompt injection turning into code execution in the Semantic Kernel framework. 
Rogue Agent did not touch the model at all. 
It abused a normal developer feature and a shared, invisible runtime, reachable with one ordinary edit permission. 
In a setup like this, a permission that looks like a content-edit right is actually a code-execution right. 
Anyone who can add a Code Block can run arbitrary Python inside a shared environment that the customer cannot inspect. 
Treat agent-edit permissions as the runtime controls they are. 
Even when the provider says nothing needs fixing, customers still have no way to look inside that runtime themselves. 
Article reasoning-pattern comparisonThis article: 2.3%Swati Khandelwal: 2.4%The Hacker News: 1.9%Confirmation Bias2.3%This article: 0.0%Swati Khandelwal: 1.5%The Hacker News: 1.2%Anchoring Bias0.0%This article: 5.7%Swati Khandelwal: 3.5%The Hacker News: 3.3%Availability Heuristic5.7%This article: 0.9%Swati Khandelwal: 1.4%The Hacker News: 1.5%Representativeness Heuristic0.9%This article: 0.0%Swati Khandelwal: 0.7%The Hacker News: 0.6%Hindsight Bias0.0%This article: 0.0%Swati Khandelwal: 2.4%The Hacker News: 2.5%Overconfidence Bias0.0%This article: 2.4%Swati Khandelwal: 2.8%The Hacker News: 2.7%Framing Effect2.4%This article: 0.0%Swati Khandelwal: 0.9%The Hacker News: 1.0%Loss Aversion0.0%This article: 2.3%Swati Khandelwal: 0.7%The Hacker News: 0.6%Status Quo Bias2.3%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%Sunk Cost Effect0.0%This article: 5.0%Swati Khandelwal: 1.2%The Hacker News: 1.3%Optimism Bias5.0%This article: 4.5%Swati Khandelwal: 1.9%The Hacker News: 1.6%Pessimism Bias4.5%This article: 16.0%Swati Khandelwal: 6.3%The Hacker News: 6.7%Negativity Bias16.0%This article: 0.0%Swati Khandelwal: 0.4%The Hacker News: 0.8%Self-Serving Bias0.0%This article: 0.0%Swati Khandelwal: 0.4%The Hacker News: 0.4%Fundamental Attribution Error0.0%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%Actor-Observer Bias0.0%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%In-Group Bias0.0%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.3%Out-Group Homogeneity Bias0.0%This article: 0.0%Swati Khandelwal: 0.4%The Hacker News: 0.6%Halo Effect0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Horn Effect0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Dunning-Kruger Effect0.0%This article: 2.3%Swati Khandelwal: 1.5%The Hacker News: 1.5%Recency Bias2.3%This article: 1.1%Swati Khandelwal: 0.2%The Hacker News: 0.3%Primacy Effect1.1%This article: 1.9%Swati Khandelwal: 0.1%The Hacker News: 0.1%Blind-Spot Bias1.9%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.1%Ad Hominem0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.1%Straw Man0.0%This article: 13.1%Swati Khandelwal: 3.9%The Hacker News: 4.0%Appeal to Authority13.1%This article: 6.8%Swati Khandelwal: 1.3%The Hacker News: 1.6%False Dilemma6.8%This article: 1.4%Swati Khandelwal: 0.7%The Hacker News: 0.5%Slippery Slope1.4%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%Circular Reasoning0.0%This article: 4.3%Swati Khandelwal: 3.8%The Hacker News: 4.3%Hasty Generalization4.3%This article: 0.0%Swati Khandelwal: 0.2%The Hacker News: 0.1%Red Herring0.0%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.2%Bandwagon0.0%This article: 4.6%Swati Khandelwal: 0.8%The Hacker News: 1.1%Appeal to Emotion4.6%This article: 0.0%Swati Khandelwal: 0.3%The Hacker News: 0.5%Begging the Question0.0%This article: 4.1%Swati Khandelwal: 2.0%The Hacker News: 1.9%Post Hoc (False Cause)4.1%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Tu Quoque0.0%This article: 0.0%Swati Khandelwal: 0.7%The Hacker News: 0.6%Burden of Proof0.0%This article: 2.8%Swati Khandelwal: 0.1%The Hacker News: 0.1%Appeal to Nature2.8%This article: 1.2%Swati Khandelwal: 0.3%The Hacker News: 0.3%Composition/Division1.2%This article: 5.1%Swati Khandelwal: 1.1%The Hacker News: 1.0%Anecdotal5.1%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%No True Scotsman0.0%This article: 6.7%Swati Khandelwal: 2.5%The Hacker News: 2.3%Ambiguity (Equivocation)6.7%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Gambler’s Fallacy0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Middle Ground0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Personal Incredulity0.0%This article: 0.0%Swati Khandelwal: 0.2%The Hacker News: 0.1%Special Pleading0.0%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%Genetic Fallacy0.0%This article: 0.0%Swati Khandelwal: 1.0%The Hacker News: 1.4%Unattributed Quote0.0%This article: 0.0%Swati Khandelwal: 0.8%The Hacker News: 0.9%Quote-first Misdirection0.0%This article: 0.0%Swati Khandelwal: 2.7%The Hacker News: 2.3%Biased Writer Voice0.0%This article: 14.2%Swati Khandelwal: 5.0%The Hacker News: 4.4%Indoctrination14.2%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Politically Left Leaning Bias0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Politically Right Leaning Bias0.0%This article: 0.0%Swati Khandelwal: 0.4%The Hacker News: 3.0%Attempt to Sell a Product or S…0.0%

980 words analyzed.

Speakers

3speakers12%attributed speech867writer words
Voice mapSelect a segment to jump to its words
Writer's voice • 12 words • 0.0% coverageWriter's voice • 31 words • 0.0% coverageWriter's voice • 25 words • 0.0% coverageVaronis • 10 words • 0.0% coverageWriter's voice • 22 words • 0.0% coverageWriter's voice • 8 words • 0.0% coverageWriter's voice • 31 words • 0.0% coverageWriter's voice • 14 words • 0.0% coverageWriter's voice • 23 words • 0.0% coverageWriter's voice • 8 words • 0.0% coverageWriter's voice • 22 words • 0.0% coverageWriter's voice • 27 words • 0.0% coverageWriter's voice • 22 words • 0.0% coverageWriter's voice • 22 words • 0.0% coverageWriter's voice • 12 words • 0.0% coverageWriter's voice • 16 words • 0.0% coverageWriter's voice • 12 words • 0.0% coverageVaronis • 17 words • 0.0% coverageWriter's voice • 12 words • 0.0% coverageWriter's voice • 18 words • 0.0% coverageWriter's voice • 18 words • 0.0% coverageWriter's voice • 18 words • 0.0% coverageWriter's voice • 20 words • 0.0% coverageWriter's voice • 20 words • 0.0% coverageWriter's voice • 15 words • 0.0% coverageWriter's voice • 20 words • 0.0% coverageWriter's voice • 6 words • 0.0% coverageVaronis • 11 words • 0.0% coverageWriter's voice • 10 words • 0.0% coverageWriter's voice • 19 words • 0.0% coverageVaronis • 19 words • 0.0% coverageWriter's voice • 25 words • 0.0% coverageWriter's voice • 21 words • 0.0% coverageWriter's voice • 10 words • 0.0% coverageWriter's voice • 27 words • 0.0% coverageWriter's voice • 5 words • 0.0% coverageWriter's voice • 24 words • 0.0% coverageWriter's voice • 13 words • 0.0% coverageWriter's voice • 12 words • 0.0% coverageVaronis • 12 words • 0.0% coverageWriter's voice • 22 words • 0.0% coverageWriter's voice • 4 words • 0.0% coverageWriter's voice • 8 words • 100.0% coverageWriter's voice • 24 words • 100.0% coverageWriter's voice • 16 words • 100.0% coverageWriter's voice • 1 words • 0.0% coverageWriter's voice • 24 words • 100.0% coverageWriter's voice • 21 words • 100.0% coverageWriter's voice • 18 words • 100.0% coverageWriter's voice • 6 words • 0.0% coverageWriter's voice • 11 words • 0.0% coverageVaronis • 15 words • 0.0% coverageNoma Security • 15 words • 0.0% coverageMicrosoft • 14 words • 0.0% coverageWriter's voice • 9 words • 0.0% coverageWriter's voice • 17 words • 0.0% coverageWriter's voice • 18 words • 0.0% coverageWriter's voice • 20 words • 0.0% coverageWriter's voice • 9 words • 100.0% coverageWriter's voice • 19 words • 100.0% coverage
Selected voice

Varonis

100%flagged-word coverage
84 attributed words74% of attributed speech66% writer coverage
0%10.0%20.0%Indoctrination-16.0 ptsWriter: 16.0%Varonis: 0.0%0.0%

Attribution is sentence-level. Pattern percentages are calculated only from words assigned to that voice.

Loading…
Loading…
Loading…
Loading…

Analysis

Hover over highlighted words in the article to view the associated bias or fallacy analysis.