Theregister
AI-Driven Command Injection Vulnerability Exposes Snowflake Jira Credentials
Article Content
A critical command injection vulnerability was discovered in Snowflake's GitHub Actions workflow, allowing unauthenticated attackers to execute arbitrary commands. The flaw was introduced by an AI coding assistant, GitHub Copilot Autofix, which altered the code on June 18, 2026. This change enabled attackers to exploit the vulnerability by opening GitHub issues with specially crafted titles, leading to the exposure of internal Jira credentials. Wiz Research's Red Agent identified the vulnerability on June 23, 2026, and disclosed it to Snowflake, which remediated the issue the same day. No evidence of malicious exploitation has been found, and the affected credentials were rotated shortly after. This incident highlights the risks associated with AI-assisted code generation in security-sensitive environments.
Key Points: • A command injection vulnerability in Snowflake's GitHub Actions workflow exposed Jira credentials. • The flaw was introduced by GitHub Copilot Autofix on June 18, 2026, and discovered by Wiz on June 23. • Snowflake remediated the vulnerability on the same day it was reported, with no evidence of exploitation.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.