CVE-2025-11449
published 2025-10-10CVE-2025-11449: ServiceNow has addressed a reflected cross-site scripting vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could result in…
PriorityP429medium5.3CVSS 4.0
AVNACLATNPRNUIPVCNVINVANSCNSILSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.32%
24.1th percentile
ServiceNow has addressed a reflected cross-site scripting vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could result in arbitrary code being executed within the browsers of ServiceNow users who click on a specially crafted link.
ServiceNow has addressed this vulnerability by deploying a relevant security update to the majority of hosted instances. Relevant security updates also have been provided to ServiceNow self-hosted customers, partners, and hosted customers with unique configuration. Further, the vulnerability is addressed in the listed patches and hot fixes. We recommend customers promptly apply appropriate updates or upgrade if they have not already done so.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| servicenow | servicenow_ai_platform | < Washington DC Patch 10 Hot Fix 7b | Washington DC Patch 10 Hot Fix 7b |
| servicenow | servicenow_ai_platform | < Xanadu Patch 10 Hot Fix 1a | Xanadu Patch 10 Hot Fix 1a |
| servicenow | servicenow_ai_platform | < Xanadu Patch 11 | Xanadu Patch 11 |
| servicenow | servicenow_ai_platform | < Yokohama Patch 7 Hot Fix 2a | Yokohama Patch 7 Hot Fix 2a |
| servicenow | servicenow_ai_platform | < Yokohama Patch 8 | Yokohama Patch 8 |
| servicenow | servicenow_ai_platform | < Yokohama Patch 9 | Yokohama Patch 9 |
| servicenow | servicenow_ai_platform | < Zurich Patch 1 Hot Fix 1a | Zurich Patch 1 Hot Fix 1a |
| servicenow | servicenow_ai_platform | < Zurich Patch 2 | Zurich Patch 2 |
| servicenow | servicenow_ai_platform | < Zurich Patch 3 | Zurich Patch 3 |
| servicenow | servicenow_ai_platform | < Australia General Availability (GA) | Australia General Availability (GA) |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-10-10
Published