Chronicle/Attacks & incidents

AppOmni shows second-order prompt injection recruiting privileged ServiceNow Now Assist agents

AttackVulnerability disclosureSignificance assistant-drafted

AppOmni reports that instructions planted in an ordinary ServiceNow record could cause a low-privilege Now Assist agent to discover and task a more privileged agent, leading to record changes, data access and email exfiltration. The behavior follows default settings that group agents into teams and make them discoverable; ServiceNow called it intended and updated its documentation.

Why it matters

It is a concrete agent-to-agent escalation where the risk lives in default configuration rather than a code bug.

Key facts

As stated in the sources, with where to find them.

  • Three defaults enable the chain: LLM support for agent discovery, automatic team grouping, and discoverable-by-default publishing.Default configuration section
  • AppOmni recommends supervised execution for privileged agents and team segmentation.Mitigations

Findings that cite this record

Key questions this bears on

Sources

Related records