Home / Companies / NeuralTrust / Blog / Post Details
Content Deep Dive

BodySnatcher: Critical ServiceNow Vulnerability (CVE-2025-12420)

Blog post from NeuralTrust

Post Details
Company
Date Published
Author
Alessandro Pignati
Word Count
2,586
Company Posts That Month
12
Language
English
Hacker News Points
-
Post removed?
No
Summary

The BodySnatcher vulnerability, identified as CVE-2025-12420, is a critical Privilege Escalation flaw found in the ServiceNow platform, notably impacting the interaction between the Virtual Agent API and Now Assist AI Agents. This flaw stems from weak security controls, such as a hardcoded credential and reliance on email addresses for user identity verification, enabling unauthenticated remote code execution. The exploit chain involves three key steps: broken API authentication via a static secret, identity hijacking using email-only linking, and the execution of privileged actions through AI agents. This vulnerability highlights the concept of Agentic Amplification, where AI agents with excessive privileges can transform minor security flaws into major threats by executing high-privilege actions based on conversational inputs. The incident underscores the necessity for robust security practices, including strong identity verification, elimination of hardcoded secrets, and the implementation of agent-specific security controls like AI guardrails and continuous monitoring. The BodySnatcher serves as a crucial reminder of the evolving security landscape, emphasizing the need for continuous trust, governance, and specialized tools to manage the complexities of agentic systems in modern enterprises.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
AI Agents 14 4,365 852 224 +29%
AI Guardrails 6 360 127 55 -16%
MCP 3 3,702 403 162 -31%
Secrets Management 2 1,271 215 97 -1%
Real-time 1 6,429 1,407 265 -24%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.