Skip to main content

SNOW-14.1: Virtual Agent Topic Without Input Sanitization

๐Ÿ”ด High ยท ServiceNow Virtual Agent

Detects Virtual Agent topics (sys_cs_topic), utterances, and topic-block scripts that process user input without sanitization. Topic-block scripts are a major prompt injection vector in conversational AI deployments.

Detailsโ€‹

FieldValue
Rule IDSNOW-14.1
SeverityHigh
CategoryServiceNow Virtual Agent
Platformsservicenow

Remediationโ€‹

Refer to the SquireX documentation for remediation guidance specific to SNOW-14.1.

See Alsoโ€‹