AI-Driven Command Injection Vulnerability Exposes Snowflake Jira Credentials

AI-Driven Command Injection Vulnerability Exposes Snowflake Jira Credentials

First seen 17 Aug 2026, 17:31 UTC News.YcombinatorTheregisterThehackernewsRescanaFeeds.Feedburner+5 67.5

Article Content

Browse articles
ThreatCluster

A critical command injection vulnerability was discovered in Snowflake's GitHub Actions workflow, allowing unauthenticated attackers to execute arbitrary commands. The flaw was introduced by an AI coding assistant, GitHub Copilot Autofix, which altered the code on June 18, 2026. This change enabled attackers to exploit the vulnerability by opening GitHub issues with specially crafted titles, leading to the exposure of internal Jira credentials. Wiz Research's Red Agent identified the vulnerability on June 23, 2026, and disclosed it to Snowflake, which remediated the issue the same day. No evidence of malicious exploitation has been found, and the affected credentials were rotated shortly after. This incident highlights the risks associated with AI-assisted code generation in security-sensitive environments.

Key Points: • A command injection vulnerability in Snowflake's GitHub Actions workflow exposed Jira credentials. • The flaw was introduced by GitHub Copilot Autofix on June 18, 2026, and discovered by Wiz on June 23. • Snowflake remediated the vulnerability on the same day it was reported, with no evidence of exploitation.

Timeline

2026-06-18
Vulnerability introduced by AI assistant
GitHub Copilot Autofix altered the workflow code, creating a command injection vector.
News.Ycombinator
2026-06-23
Vulnerability discovered and disclosed
Wiz Research's Red Agent identified the flaw and reported it to Snowflake via HackerOne.
Rescana
2026-06-23
Snowflake patches the vulnerability
Snowflake remediated the issue within hours of disclosure and rotated the affected credentials.
Theregister
2026-06-24
Credentials rotated
Snowflake rotated the exposed Jira API token to mitigate potential risks.
Rescana
2026-08-18
Public disclosure of incident
The incident was publicly reported, emphasizing the risks of AI in code generation.
Thehackernews