CVE-2025-13427: Google Cloud Dialogflow Cx Messenger

Medium severity, CVSS 6.9. EPSS: 0.5% chance of exploitation in the next 30 days.

An authentication bypass vulnerability in Google Cloud Dialogflow CX Messenger allowed unauthenticated users to interact with restricted chat agents, gaining access to the agents' knowledge and the ability to trigger their intents, by manipulating initialization parameters or crafting specific API requests. All versions after August 20th, 2025 have been updated to protect from this vulnerability. No user action is required for this.

Affected products

  • Google Cloud Dialogflow Cx Messenger: up to and including 2025-08-20

Published 2025-12-18. Last modified 2026-09-30.