SNOW-2.1: Unsafe Script Pattern in Agent Tool
๐จ Critical ยท ServiceNow Script Safety
Detects unsafe scripting patterns in agent-accessible Script Includes and Script Tools. Patterns include eval(), GlideEvaluator, Packages.java, GlideSystemScript, and direct SQL via GlideDBQuery โ all of which can be exploited through prompt injection to achieve remote code execution.
Detailsโ
| Field | Value |
|---|---|
| Rule ID | SNOW-2.1 |
| Severity | Critical |
| Category | ServiceNow Script Safety |
| Platforms | servicenow |
Remediationโ
Refer to the SquireX documentation for
remediation guidance specific to SNOW-2.1.