Wiz AI Agent Finds Critical Script Injection in Snowflake
π Security researchers at Wiz, part of Google Cloud, discovered a critical script injection vulnerability in Snowflakeβs public GitHub repository that GitHub Advanced Security missed. The issue, found by Wiz Researchβs autonomous Red Agent on June 23, allowed unauthenticated command execution in a GitHub Actions runner via a crafted issue title. Snowflake patched the workflow and rotated the Jira token after being notified via HackerOne, reporting no evidence of unauthorized access.
