Google Cloud Dialogflow CX Messenger Authentication Bypass Vulnerability

Vulnerability

A vulnerability allowing authentication bypass in Google Cloud Dialogflow CX Messenger integration was identified. This issue enabled unauthenticated users to interact with restricted chat agents, access their knowledge, and trigger intents by manipulating initialization parameters or crafting specific API requests. All versions released after August 20, 2025, have been patched, and no user action is required.

Impact

Exploitation of this vulnerability allowed unauthorized access to restricted chat agents, enabling interaction with the agents' knowledge and the ability to trigger their intents.

Added: Dec 18, 2025, 10:30 PM
Updated: Dec 18, 2025, 10:30 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
3.1
exploitability
7.4
remediation
7.7
relevance
1.6
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.