‘BodySnatcher’ AI Vulnerability in ServiceNow Exposes How Dangerous Overpowered Agents Can Be
A newly detailed flaw in ServiceNow’s Now Assist AI platform, dubbed ‘BodySnatcher’ (CVE-2025-12420), shows how weak authentication and over-privileged AI agents could have let attackers impersonate any user — including admins — across thousands of enterprises.