Severity: CriticalVulnerabilityPrompt injection
Cross-agent privilege escalation in Google Dialogflow CX Code Block components
Global
Live intelligence. Items are aggregated from public sources and summarised automatically. Always verify against the linked source before acting.
A critical flaw in Google Dialogflow CX allowed an attacker with edit permissions on one Code Block-enabled agent to compromise other Code Block-enabled agents within the same Google Cloud project. This could enable interception of live conversations, exfiltration of user data, and injection of attacker-controlled messages into conversations.
What to do
Audit all Code Block-enabled agents in shared Google Cloud projects and enforce least-privilege IAM permissions to isolate agent edit access by role.
Mapped framework pillars
Sources
#Dialogflow CX#Code Block#agent hijacking#multi-tenant#GCP#chatbot security
