Rogue Agent Watch › Records › servicenow-now-assist-agent-injection

ServiceNow Now Assist agent-to-agent prompt injection (insecure defaults)

Disclosed · added to the index · last updated

Grades

Verification status
Reported — Publicly reported but not independently confirmed. Never present a reported incident as confirmed.
Sourcing confidence
Primary — Backed by primary sourcing — first-party disclosure, vendor incident report, government advisory, or court documents.
AI role
Load-bearing — AI was central — the operation as described could not have happened at this scale or in this form without it.
Severity
High — Significant confirmed harm to one or more organizations.

Summary

In November 2025 AppOmni disclosed a second-order, agent-to-agent prompt- injection weakness in ServiceNow's Now Assist agentic AI. Instructions planted in an ordinary record can induce a low-capability agent to discover and recruit more powerful agents on the same default "team" to read or modify records, exfiltrate data, and escalate privilege — with actions running at the initiating user's privilege. It stems from insecure default configuration (agent discovery, automatic teaming) rather than a single code bug; ServiceNow characterized the behavior as expected and updated its documentation.

Impact as stated

Researcher demonstration: showed that default Now Assist agent-discovery and teaming can turn a benign agent into a vector for unauthorized data access, modification, exfiltration and privilege escalation. No in-the-wild exploitation reported.

Facts as stated by sources

Actor
AppOmni (AO Labs) (Researcher)
Category
Agent hijack / prompt injection
Models named
not named by sources
Model families
Other / unspecified
Agentic autonomy level
Not applicable
Guardrail bypass
Indirect prompt injection
Attack lifecycle phases
Initial access, Execution, Privilege escalation, Exfiltration
Target sectors
not stated
Target countries
not stated
Organisations affected
not stated
Records exfiltrated
not stated

Framework mappings

MITRE ATLAS
AML.T0051.001, AML.T0053, AML.T0057
OWASP LLM Top 10
LLM01

Mitigations as stated

  • Enable supervised execution mode for privileged agents; disable the autonomous override property; segment agents into separate teams; monitor agent behavior.

Map

No cited source states a location; this record is listed beside the map, never plotted.

Related records

Sources (2)

  1. When AI Turns on Its Team: Exploiting Agent-to-Agent Discovery via Prompt Injection
    AppOmni · First-party disclosure · · archived copy
  2. ServiceNow AI Agents Can Be Tricked Into Acting Against Each Other via Second-Order Prompts
    The Hacker News · News · · archived copy

Cite this record

Agentic Attack Index (MLSecOpsHub), dataset v0.3.0, record "servicenow-now-assist-agent-injection". https://raw.githubusercontent.com/MLSecOpsHub/agentic-attack-index/main/dist/incidents/servicenow-now-assist-agent-injection.json — CC BY-SA 4.0.

Record JSON · Source YAML · Report a correction