{"id":9188,"date":"2026-08-19T11:09:07","date_gmt":"2026-08-19T11:09:07","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=9188"},"modified":"2026-08-19T11:09:07","modified_gmt":"2026-08-19T11:09:07","slug":"snowflake-flaw-slips-past-ai-checks-gets-exploited-by-another-ai","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=9188","title":{"rendered":"Snowflake flaw slips past AI checks, gets exploited by another AI"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">An autonomous AI security agent developed by cloud security firm Wiz identified and exploited a critical vulnerability in Snowflake\u2019s GitHub Actions pipeline, while GitHub Copilot had previously reviewed the code change without flagging the flaw.<\/p>\n<p class=\"wp-block-paragraph\">The vulnerable code was part of a pull request (PR) that GitHub Copilot was involved in, though Wiz has clarified that it is unclear whether the coding assistant itself introduced the vulnerability. \u201cCopilot was a co-author that checked the merged PR and code change, and identified it as all-clear without noticing the critical vulnerabilities,\u201d Wiz researchers said in a blog <a href=\"https:\/\/www.wiz.io\/blog\/red-agent-snowflake-copilot-cicd-bug\" target=\"_blank\" rel=\"noopener\">post<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">The attack path was identified and exploited using Wiz\u2019s autonomous security research tool \u201cRed Agent,\u201d which ultimately managed to access Snowflake\u2019s internal Jira credentials.<\/p>\n<p class=\"wp-block-paragraph\">Wiz initially faced critical feedback as the disclosure appeared to suggest that Copilot had helped write the flawed code, which the company later updated with clarifications. \u201cIn a world where multiple agents run on every PR, scan it and update it, clear attribution between humans and AI is becoming a bit harder to establish; just looking at co-authors of the PR is not enough,\u201d Wiz co-founder and CTO <a href=\"https:\/\/www.linkedin.com\/in\/amiluttwak\/\" target=\"_blank\" rel=\"noopener\">Ami Luttwak<\/a> told CSO.<\/p>\n<p class=\"wp-block-paragraph\">Snowflake remediated the vulnerability on June 23, the same day Wiz reported it to the company through its HackerOne <a href=\"https:\/\/hackerone.com\/snowflake?type=team\" target=\"_blank\" rel=\"noopener\">program<\/a>. The vulnerability \u201cwas immediately investigated and remediated, and our investigation found no evidence of unauthorized access,\u201d a Snowflake spokesperson told CSO.<\/p>\n<h2 class=\"wp-block-heading\"><a><\/a>Flaw exploited despite protections<\/h2>\n<p class=\"wp-block-paragraph\">Wiz\u2019s Red Agent found the flaw in the \u201cjira_issue.yml\u201d workflow in Snowflake\u2019s \u201csnowflake-connector-net\u201d repository.<\/p>\n<p class=\"wp-block-paragraph\">The workflow ran whenever someone opened a GitHub issue and used the issue title as part of a shell command. A change introduced in PR#1218 altered the way this input was handled, allowing an attacker to inject and execute their own commands through the workflow, the researchers explained.<\/p>\n<p class=\"wp-block-paragraph\">The workflow also contained a protection designed to prevent exploitation by untrusted users. But that check was ineffective because it was built for a pull request, but the exploit involved handling \u201cissues\u201d. Consequently, the check did not work as intended, allowing any GitHub user to get past it.<\/p>\n<p class=\"wp-block-paragraph\">The vulnerability went live on June 18, when PR#1218 was merged. Wiz said GitHub Advanced Security had scanned the final revision and extracted the vulnerable workflow but failed to flag the injection.<\/p>\n<h2 class=\"wp-block-heading\"><a><\/a>Red Agent hacked the credentials<\/h2>\n<p class=\"wp-block-paragraph\">Wiz\u2019s Red Agent discovered the vulnerability while autonomously scanning Snowflake\u2019s GitHub organization. It then crafted a malicious issue title designed to break out of the shell\u2019s \u201cecho\u201d statement and send the Jira credentials to an external listener.<\/p>\n<p class=\"wp-block-paragraph\">The researchers noted that Red Agent\u2019s first attempt at exploitation had failed due to a syntax error, but the agent then analyzed the error, modified its payload, and built a successful exploit in the second attempt, all by itself.<\/p>\n<p class=\"wp-block-paragraph\">The successful exploitation had the <a href=\"https:\/\/www.csoonline.com\/article\/4188144\/github-actions-hardens-checkout-security-to-block-pwn-request-attacks-2.html\">GitHub Actions<\/a> runner send an out-of-band callback containing base64-encoded Jira credentials. Wiz used the credentials to authenticate to Snowflake\u2019s internal <a href=\"https:\/\/www.csoonline.com\/article\/4207306\/one-click-flaw-in-atlassian-rovo-exposed-enterprise-data-via-prompt-injection-attack.html\">Atlassian <\/a>environment, gaining read access to engineering, security compliance, and bug bounty projects.<\/p>\n<p class=\"wp-block-paragraph\">The vulnerability had been live for five days when Redd Agent found it, Wiz said. Snowflake patched the workflow on June 23, restoring the safer input-handling pattern, and rotated the affected Jira credential the following day. Snowflake\u2019s forensic investigation found no evidence of access by anyone other than Wiz during the exposure window. Wiz also confirmed that all data accessed during proof-of-concept testing was securely deleted.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>An autonomous AI security agent developed by cloud security firm Wiz identified and exploited a critical vulnerability in Snowflake\u2019s GitHub Actions pipeline, while GitHub Copilot had previously reviewed the code change without flagging the flaw. The vulnerable code was part of a pull request (PR) that GitHub Copilot was involved in, though Wiz has clarified [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":9189,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-9188","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9188"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9188"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9188\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/9189"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9188"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9188"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9188"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}