Impact
The flaw is a sandbox escape (CWE‑94) that allows an unauthenticated attacker to run arbitrary code inside the ServiceNow AI Platform. This remote code execution could grant full control over the application environment, enabling the attacker to read, modify, or delete data and potentially pivot to other systems.
Affected Systems
Any deployment of the ServiceNow AI Platform, whether hosted by ServiceNow or self‑hosted on customer premises, is affected. The fix has been released for all hosted instances and for self‑hosted customers and partners through specific security updates or family releases.
Risk and Exploitability
The CVSS score of 9.5 marks it as critical. The EPSS score of 24% and its absence from CISA's KEV catalog indicate a significant current exploitation likelihood, but the vulnerability could still be exploited if a suitable attack vector was discovered. The attack vector is suspected to be an unauthenticated request to the AI Platform’s API or interface, though that is inferred from the description.
OpenCVE Enrichment