Rogue Agent Watch › Records › servicenow-now-assist-agent-injection
ServiceNow Now Assist agent-to-agent prompt injection (insecure defaults)
Disclosed · added to the index · last updated
Grades
- Verification status
- Reported — Publicly reported but not independently confirmed. Never present a reported incident as confirmed.
- Sourcing confidence
- Primary — Backed by primary sourcing — first-party disclosure, vendor incident report, government advisory, or court documents.
- AI role
- Load-bearing — AI was central — the operation as described could not have happened at this scale or in this form without it.
- Severity
- High — Significant confirmed harm to one or more organizations.
Summary
In November 2025 AppOmni disclosed a second-order, agent-to-agent prompt- injection weakness in ServiceNow's Now Assist agentic AI. Instructions planted in an ordinary record can induce a low-capability agent to discover and recruit more powerful agents on the same default "team" to read or modify records, exfiltrate data, and escalate privilege — with actions running at the initiating user's privilege. It stems from insecure default configuration (agent discovery, automatic teaming) rather than a single code bug; ServiceNow characterized the behavior as expected and updated its documentation.
Impact as stated
Researcher demonstration: showed that default Now Assist agent-discovery and teaming can turn a benign agent into a vector for unauthorized data access, modification, exfiltration and privilege escalation. No in-the-wild exploitation reported.
Facts as stated by sources
- Actor
- AppOmni (AO Labs) (Researcher)
- Category
- Agent hijack / prompt injection
- Models named
- not named by sources
- Model families
- Other / unspecified
- Agentic autonomy level
- Not applicable
- Guardrail bypass
- Indirect prompt injection
- Attack lifecycle phases
- Initial access, Execution, Privilege escalation, Exfiltration
- Target sectors
- not stated
- Target countries
- not stated
- Organisations affected
- not stated
- Records exfiltrated
- not stated
Framework mappings
- MITRE ATLAS
- AML.T0051.001, AML.T0053, AML.T0057
- OWASP LLM Top 10
- LLM01
Mitigations as stated
- Enable supervised execution mode for privileged agents; disable the autonomous override property; segment agents into separate teams; monitor agent behavior.
Map
No cited source states a location; this record is listed beside the map, never plotted.
Related records
Sources (2)
- When AI Turns on Its Team: Exploiting Agent-to-Agent Discovery via Prompt Injection
AppOmni · First-party disclosure · · archived copy - ServiceNow AI Agents Can Be Tricked Into Acting Against Each Other via Second-Order Prompts
The Hacker News · News · · archived copy
Cite this record
Agentic Attack Index (MLSecOpsHub), dataset v0.3.0, record "servicenow-now-assist-agent-injection". https://raw.githubusercontent.com/MLSecOpsHub/agentic-attack-index/main/dist/incidents/servicenow-now-assist-agent-injection.json — CC BY-SA 4.0.