Theregister
AI Vulnerability in Snowflake's GitHub Repo Exploited by Autonomous Agent
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A critical vulnerability was discovered in Snowflake's GitHub Actions workflow, allowing unauthorized command execution. The flaw was identified by Wiz Research's AI tool, Red Agent, during a sanctioned bug hunt on June 23, 2026. The vulnerability, introduced by GitHub Copilot Autofix on June 18, 2026, involved a script injection attack via specially crafted GitHub issue titles. This allowed an unauthenticated user to execute arbitrary commands within a GitHub Actions runner. Snowflake remediated the issue on the same day it was reported and confirmed that Wiz was the only entity to access the exposed data. The incident emphasizes the risks posed by AI coding assistants in software development. Wiz deleted all accessed data and highlighted the inadequacy of human code reviews in detecting such vulnerabilities. Snowflake is collaborating with Wiz to share lessons learned with the industry.
Key Points: • A GitHub Actions vulnerability allowed unauthorized command execution in Snowflake's repo. • The flaw was introduced by GitHub Copilot Autofix just five days before its discovery. • Wiz's AI tool autonomously exploited the vulnerability during a sanctioned security assessment.