Skip to main content

SNOW-5.1: Flow Action Without Input Validation

๐Ÿ”ด High ยท ServiceNow Flow Security

Detects Flow Designer actions (sys_hub_action) and subflows linked to AI agents that lack input validation or execute in system context. When an AI agent invokes a flow action, the parameters are formatted as strings for LLM processing, enabling variable injection if inputs are not validated.

Detailsโ€‹

FieldValue
Rule IDSNOW-5.1
SeverityHigh
CategoryServiceNow Flow Security
Platformsservicenow

Remediationโ€‹

Refer to the SquireX documentation for remediation guidance specific to SNOW-5.1.

See Alsoโ€‹