Skip to content
Agentic AI Security Hub
Back to feed
Severity: CriticalVulnerabilityPrompt injection

Cross-agent privilege escalation in Google Dialogflow CX Code Block components

Global

Live intelligence. Items are aggregated from public sources and summarised automatically. Always verify against the linked source before acting.

A critical flaw in Google Dialogflow CX allowed an attacker with edit permissions on one Code Block-enabled agent to compromise other Code Block-enabled agents within the same Google Cloud project. This could enable interception of live conversations, exfiltration of user data, and injection of attacker-controlled messages into conversations.

What to do

Audit all Code Block-enabled agents in shared Google Cloud projects and enforce least-privilege IAM permissions to isolate agent edit access by role.

#Dialogflow CX#Code Block#agent hijacking#multi-tenant#GCP#chatbot security