Skip to main content

SNOW-24.1: Agent API Endpoint Without OAuth Scope Validation

๐Ÿ”ด High ยท ServiceNow API Authentication

Detects Scripted REST APIs and Now Assist API endpoints accessible to AI agents that lack OAuth entity scope validation. Without scope constraints, any OAuth client can invoke agent-specific endpoints.

Detailsโ€‹

FieldValue
Rule IDSNOW-24.1
SeverityHigh
CategoryServiceNow API Authentication
Platformsservicenow

Remediationโ€‹

Refer to the SquireX documentation for remediation guidance specific to SNOW-24.1.

See Alsoโ€‹