HomeSecurityRogue Agent vulnerability could allow Google Dialogflow chatbots to be hijacked...

Rogue Agent vulnerability could allow Google Dialogflow CX chatbots to be hijacked

A critical vulnerability in Dialogflow CX could allow an attacker with edit permissions on an agent with Code Block enabled to compromise other agents with Code Block enabled in the same Google Cloud project. From there, they could read live conversations, steal data shared by users, and cause bots to send messages written by the attacker, including password reset requests.

See also: RoguePlanet Zero-Day: New Microsoft Defender vulnerability gives SYSTEM access

Article Image: Rogue Agent Flaw Could Have Let Attackers Hijack Google Dialogflow CX Chatbots
Rogue Agent vulnerability could allow Google Dialogflow CX chatbots to be hijacked

Security firm Varonis discovered the vulnerability and dubbed it Rogue Agent. The vulnerability only affected organizations that had built agents with Dialogflow Playbooks and custom Code Blocks, which allow developers to add their own Python code. It was not a remote, unauthenticated attack. To carry it out, the dialogflow.playbooks.update on such an agent was required, which limits the realistic attacker to a malicious internal user or a compromised developer account, not someone unknown on the internet. From that single point of access, however, the reach extended to every agent in the project.

Google has fixed the problem, and both Varonis and Google state that there is no evidence that the vulnerability was ever used in an actual attack.

Dialogflow Code Blocks allow developers to add custom Python code to a chatbot's conversation flow to control input, control behavior, and call specified tools. This code runs in a Google-managed Cloud Run environment, and each agent using Code Blocks in the same Google Cloud project shares an instance of it.

Google manages this environment, the customer cannot see or control it, and Varonis found no real isolation between agents within it.

When an agent executes a Code Block, the developer's code is added to the internal setup code and passed to the Python exec() function. This setup code defines the variables and functions that the block can touch. The variables include history for the entire conversation and state for session details like the session ID. The functions include respond(), which makes the bot respond with a given string.

See also: Prompt Injection Flaw in Vanna AI Exposes Databases to RCE Attacks

Rogue Agent vulnerability could allow Google Dialogflow CX chatbots to be hijacked
Rogue Agent vulnerability could allow Google Dialogflow CX chatbots to be hijacked

Varonis found the file that does this wrapping, code_execution_env.py, in the shared environment with write permissions. Because this file was writable, only one Code Block could replace it. This block downloads a modified code_execution_env.py from a server controlled by the attacker and replaces the original one inside the running container.

From there, the attacker's version is executed for every Code Block execution on every agent that shares that environment. It is in the same scope as the legitimate code, with the same access to history, state, and respond().

This allows it to read every conversation, silently send it to the attacker's server, and have the bot post messages written by the attacker. An example is phishing: the bot asks the user to re-verify a connection, and the attacker collects what they type. To cover their tracks, the attacker restores the original Code Block to the Dialogflow console. This only changes what the console displays; the replaced file is already running in the container and continues to run underneath.

Varonis reported two related issues, neither of which required a file replacement. First, the Code Block environment had uncontrolled outbound access to the internet. Using the built-in urllib library, the researchers sent data directly to an external server and were able to receive commands back. Varonis says this bypasses VPC Service Controls, Google Cloud's perimeter that is intended to stop data from leaving protected services.

The environment lies outside this perimeter and can reach the open internet, which turns it into a channel for both data theft and remote control.

See also: Learn all about Microsoft's Agent Governance Toolkit

Google Translate settings
Rogue Agent vulnerability could allow Google Dialogflow CX chatbots to be hijacked

Second, and less seriously, the environment exposed the Instance Metadata Service (IMDS), a normally internal point that provides cloud credentials. The query returned a token for a service account managed by Google. This account had low privileges, so the immediate risk was limited; the real point is that a code execution sandbox shouldn't be able to reach IMDS at all.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS