Back to news
AI Tools & Products
Aug 17, 2026

Snowflake Addresses GitHub Workflow Vulnerability Discovered by AI Security Tool

Aug 17, 2026
AI Summary

A critical vulnerability in Snowflake's GitHub repository was identified by Wiz Research's AI tool, Red Agent. The issue, which allowed unauthorized command execution, was discovered just five days after it was introduced, prompting immediate remediation by Snowflake.

Wiz Research's Red Agent identified a script injection vulnerability in Snowflake's public GitHub repository, snowflakedb/snowflake-connector-net.

The vulnerability was introduced on June 18, 2026, when a pull request was merged, co-authored by GitHub's Copilot Autofix. It allowed an unauthenticated user to execute arbitrary commands by exploiting a GitHub Actions workflow.

Wiz responsibly disclosed the vulnerability to Snowflake on June 23, 2026, leading to immediate remediation, including credential rotation and a thorough audit confirming no unauthorized access.

The vulnerability was live for only five days, highlighting the need for rapid patch cycles in the face of automated security discovery.

Snowflake restored the safe coding practices in the workflow on the same day of disclosure and emphasized the importance of rigorous oversight for AI-generated code to prevent security regressions.

githubai-generatedsecurityjiradevops