{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.1",
    "cveMetadata": {
        "cveId": "CVE-2025-11450",
        "assignerOrgId": "303448ea-6ef3-4077-ad29-5c9bf253c375",
        "state": "PUBLISHED",
        "assignerShortName": "SN",
        "dateReserved": "2025-10-07T16:35:36.679Z",
        "datePublished": "2025-10-10T01:09:54.850Z",
        "dateUpdated": "2025-10-10T14:40:03.256Z"
    },
    "containers": {
        "cna": {
            "affected": [
                {
                    "defaultStatus": "unaffected",
                    "product": "ServiceNow AI Platform",
                    "vendor": "ServiceNow",
                    "versions": [
                        {
                            "lessThan": "Washington DC Patch 10 Hot Fix 7b",
                            "status": "affected",
                            "version": "0",
                            "versionType": "custom"
                        },
                        {
                            "lessThan": "Xanadu Patch 10 Hot Fix 1a",
                            "status": "affected",
                            "version": "0",
                            "versionType": "custom"
                        },
                        {
                            "lessThan": "Xanadu Patch 11",
                            "status": "affected",
                            "version": "0",
                            "versionType": "custom"
                        },
                        {
                            "lessThan": "Yokohama Patch 7 Hot Fix 2a",
                            "status": "affected",
                            "version": "0",
                            "versionType": "custom"
                        },
                        {
                            "lessThan": "Yokohama Patch 8",
                            "status": "affected",
                            "version": "0",
                            "versionType": "custom"
                        },
                        {
                            "lessThan": "Yokohama Patch 9",
                            "status": "affected",
                            "version": "0",
                            "versionType": "custom"
                        },
                        {
                            "lessThan": "Zurich Patch 1 Hot Fix 1a",
                            "status": "affected",
                            "version": "0",
                            "versionType": "custom"
                        },
                        {
                            "lessThan": "Zurich Patch 2",
                            "status": "affected",
                            "version": "0",
                            "versionType": "custom"
                        },
                        {
                            "lessThan": "Zurich Patch 3",
                            "status": "affected",
                            "version": "0",
                            "versionType": "custom"
                        },
                        {
                            "lessThan": "Australia General Availability (GA)",
                            "status": "affected",
                            "version": "0",
                            "versionType": "custom"
                        }
                    ]
                }
            ],
            "credits": [
                {
                    "lang": "en",
                    "type": "finder",
                    "value": "Adam Kues - Assetnote"
                },
                {
                    "lang": "en",
                    "type": "finder",
                    "value": "Shubham Shah - Assetnote"
                }
            ],
            "descriptions": [
                {
                    "lang": "en",
                    "supportingMedia": [
                        {
                            "base64": false,
                            "type": "text/html",
                            "value": "ServiceNow has addressed a reflected cross-site scripting vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could result in arbitrary code being executed within the browsers of ServiceNow users who click on a specially crafted link.  <br><br>ServiceNow has addressed this vulnerability by deploying a relevant security update to the majority of hosted instances.  Relevant security updates also have been provided to ServiceNow self-hosted customers, partners, and hosted customers with unique configurations. Further, the vulnerability is addressed in the listed patches and hot fixes. We recommend customers promptly apply appropriate updates or upgrade if they have not already done so. <br>"
                        }
                    ],
                    "value": "ServiceNow has addressed a reflected cross-site scripting vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could result in arbitrary code being executed within the browsers of ServiceNow users who click on a specially crafted link.  \n\nServiceNow has addressed this vulnerability by deploying a relevant security update to the majority of hosted instances.  Relevant security updates also have been provided to ServiceNow self-hosted customers, partners, and hosted customers with unique configurations. Further, the vulnerability is addressed in the listed patches and hot fixes. We recommend customers promptly apply appropriate updates or upgrade if they have not already done so."
                }
            ],
            "metrics": [
                {
                    "cvssV4_0": {
                        "Automatable": "NOT_DEFINED",
                        "Recovery": "NOT_DEFINED",
                        "Safety": "NOT_DEFINED",
                        "attackComplexity": "LOW",
                        "attackRequirements": "NONE",
                        "attackVector": "NETWORK",
                        "baseScore": 5.3,
                        "baseSeverity": "MEDIUM",
                        "privilegesRequired": "NONE",
                        "providerUrgency": "NOT_DEFINED",
                        "subAvailabilityImpact": "NONE",
                        "subConfidentialityImpact": "NONE",
                        "subIntegrityImpact": "LOW",
                        "userInteraction": "PASSIVE",
                        "valueDensity": "NOT_DEFINED",
                        "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N",
                        "version": "4.0",
                        "vulnAvailabilityImpact": "NONE",
                        "vulnConfidentialityImpact": "NONE",
                        "vulnIntegrityImpact": "NONE",
                        "vulnerabilityResponseEffort": "NOT_DEFINED"
                    },
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "GENERAL"
                        }
                    ]
                }
            ],
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "cweId": "CWE-79",
                            "description": "CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')",
                            "lang": "en",
                            "type": "CWE"
                        }
                    ]
                }
            ],
            "providerMetadata": {
                "orgId": "303448ea-6ef3-4077-ad29-5c9bf253c375",
                "shortName": "SN",
                "dateUpdated": "2025-10-10T01:09:54.850Z"
            },
            "references": [
                {
                    "url": "https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB2552817"
                }
            ],
            "source": {
                "discovery": "UNKNOWN"
            },
            "title": "Reflected Cross Site Scripting in ServiceNow AI Platform",
            "x_generator": {
                "engine": "Vulnogram 0.2.0"
            }
        },
        "adp": [
            {
                "metrics": [
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "timestamp": "2025-10-10T14:39:48.553708Z",
                                "id": "CVE-2025-11450",
                                "options": [
                                    {
                                        "Exploitation": "none"
                                    },
                                    {
                                        "Automatable": "no"
                                    },
                                    {
                                        "Technical Impact": "partial"
                                    }
                                ],
                                "role": "CISA Coordinator",
                                "version": "2.0.3"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2025-10-10T14:40:03.256Z"
                }
            }
        ]
    }
}