BodySnatcher: Critical ServiceNow Vulnerability (CVE-2025-12420)
Blog post from NeuralTrust
The BodySnatcher vulnerability, identified as CVE-2025-12420, is a critical Privilege Escalation flaw found in the ServiceNow platform, notably impacting the interaction between the Virtual Agent API and Now Assist AI Agents. This flaw stems from weak security controls, such as a hardcoded credential and reliance on email addresses for user identity verification, enabling unauthenticated remote code execution. The exploit chain involves three key steps: broken API authentication via a static secret, identity hijacking using email-only linking, and the execution of privileged actions through AI agents. This vulnerability highlights the concept of Agentic Amplification, where AI agents with excessive privileges can transform minor security flaws into major threats by executing high-privilege actions based on conversational inputs. The incident underscores the necessity for robust security practices, including strong identity verification, elimination of hardcoded secrets, and the implementation of agent-specific security controls like AI guardrails and continuous monitoring. The BodySnatcher serves as a crucial reminder of the evolving security landscape, emphasizing the need for continuous trust, governance, and specialized tools to manage the complexities of agentic systems in modern enterprises.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| AI Agents | 14 | 4,365 | 852 | 224 | +29% |
| AI Guardrails | 6 | 360 | 127 | 55 | -16% |
| MCP | 3 | 3,702 | 403 | 162 | -31% |
| Secrets Management | 2 | 1,271 | 215 | 97 | -1% |
| Real-time | 1 | 6,429 | 1,407 | 265 | -24% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.