Security Center - Escape Jelly Script
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-01-2026 12:54 PM
Hi everyone,
We are planning to enable the Escape Jelly Script hardening setting in ServiceNow Security Center.
Has anyone enabled this setting before? What areas should be tested, and are there any known impacts or issues after enabling it?
Thank you!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-01-2026 08:47 PM
For my client project , it has been set to true 9 yrs ago!
Escape jelly script [Updated in Security Center 1.3 and 1.5]
Note: For security hardening changes, I generally prefer deploying them to UAT and leaving them there for about a month so business users have sufficient time to test and provide feedback before we proceed further.
Will suggest you -
- Apply this setting in a Sub-Production (Dev/Test) environment first.
- Focus your regression testing on UI Pages, UI Macros, and content blocks that rely heavily on custom Jelly XML scripting
- Utilize the studio->Code search tool to look for custom Jelly tags that pass unescaped variables
Regards
Tanushree Maiti
ServiceNow Technical Architect
LinkedIn: https://www.linkedin.com/in/tanushreemaiti