Organizations/platform

ServiceNow

1 records1 attackWebsite
Nov 19, 2025
AppOmni shows second-order prompt injection recruiting privileged ServiceNow Now Assist agents
AttackVulnerability disclosureAppOmni, ServiceNow

AppOmni reports that instructions planted in an ordinary ServiceNow record could cause a low-privilege Now Assist agent to discover and task a more privileged agent, leading to record changes, data access and email exfiltration. The behavior follows default settings that group agents into teams and make them discoverable; ServiceNow called it intended and updated its documentation.