Impact
This vulnerability is a code injection flaw in the ServiceNow AI Platform that allows an attacker without authentication to run arbitrary code on the platform and access or alter data beyond intended limits. The weakness is a classic code injection issue, enabling execution of malicious payloads through improperly validated GraphQL Composite Data API input.
Affected Systems
The affected product is the ServiceNow AI Platform. No specific version numbers are disclosed in the advisory; the vulnerability applies to all instances of the platform that have not yet been patched.
Risk and Exploitability
The CVSS score of 10 reflects a critical impact, and the vulnerability is not currently listed in CISA KEV and no EPSS score is available. Although no malicious exploitation has been reported, the vulnerability can be triggered by an unauthenticated user targeting the GraphQL API, suggesting that attackers could achieve full remote code execution and compromise the platform if the patch is not applied.
OpenCVE Enrichment