Quick Summary
The Securityish Brief
ServiceNow disclosed a critical security flaw in its AI Platform, identified as CVE-2025-12420, which could enable unauthenticated users to impersonate legitimate users and perform unauthorized actions. This vulnerability received a CVSS score of 9.3 out of 10, indicating its severity. The issue was reported by Aaron Costello, chief of SaaS Security Research at AppOmni, in October 2025 and was patched on October 30, 2025.
The flaw impacts various components of the ServiceNow AI Platform, including Now Assist AI Agents and the Virtual Agent API. Specifically, the versions that include a fix are Now Assist AI Agents (sn_aia) – 5.1.18 or later and 5.2.19 or later, and Virtual Agent API (sn_va_as_service) – 3.15.2 or later and 4.0.4 or later. While there is no evidence of exploitation in the wild, the potential for unauthorized access poses significant risks.
This disclosure follows a previous report by AppOmni, which highlighted that attackers could exploit default configurations in ServiceNow’s Now Assist generative AI platform to conduct second-order prompt injection attacks. Such vulnerabilities can lead to unauthorized actions, data exfiltration, and privilege escalation.
Understanding the Risks
The implications of CVE-2025-12420 are considerable for organizations using ServiceNow’s AI Platform. The ability for an unauthenticated user to impersonate another user can lead to severe data breaches, unauthorized access to sensitive information, and potential regulatory repercussions. Organizations must prioritize applying the security updates to mitigate these risks.
As cybersecurity threats evolve, the incident underscores the importance of maintaining up-to-date software and configurations. Organizations should regularly review their security settings and ensure that all components of their systems are patched against known vulnerabilities.
Users and organizations leveraging ServiceNow should remain vigilant for any unusual activity within their accounts and systems. Implementing additional security measures, such as multi-factor authentication, can further protect against unauthorized access.
Key Takeaways
- Apply the latest security updates for ServiceNow AI Platform components immediately to mitigate risks associated with CVE-2025-12420.
- Review and update configurations to ensure they are not vulnerable to exploitation.
- Monitor user activity for any signs of unauthorized access or unusual behavior.
- Consider implementing multi-factor authentication to enhance account security.
- Stay informed about future vulnerabilities and security advisories related to your software and platforms.
Key Terms & Concepts
- CVE-2025-12420: In this article, CVE-2025-12420 refers to a critical vulnerability in ServiceNow’s AI Platform that allows unauthenticated user impersonation.
- CVSS: CVSS stands for Common Vulnerability Scoring System, which is used to assess the severity of security vulnerabilities.
- Now Assist AI Agents: Now Assist AI Agents are a component of ServiceNow’s AI Platform that can be affected by security vulnerabilities.
- Virtual Agent API: The Virtual Agent API is another component of ServiceNow’s platform that enables automated interactions and can also be vulnerable to exploits.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.