Threat · curated 17 Aug 2026

Red Agent Exploits Snowflake Vuln Created by Copilot Autofix

Dossier

Coverage timeline

17 Aug 2026wiz.ioprimarytheregister.comthehackernews.com 19 Aug 2026cypro.co.uk

Why it matters

The Snowflake incident is a concrete demonstration of both sides of AI risk in software supply chains: an AI coding assistant silently introduced an exploitable command-injection flaw that passed AI review, and an autonomous AI agent independently found, iterated on, and successfully exploited it to steal credentials.

Wiz Research's autonomous AI-powered 'Red Agent' discovered and exploited a script/command-injection vulnerability in the jira_issue.yml GitHub Actions workflow of Snowflake's snowflake-connector-net repository, where an attacker-controlled issue title was interpolated directly into a shell command. The flaw was introduced days earlier by a commit co-authored by GitHub Copilot Autofix, which removed a safe input-sanitization pattern; Red Agent crafted a malicious issue title to break out of the echo statement and exfiltrate base64-encoded internal Jira credentials, then authenticated to Snowflake's Atlassian environment. Snowflake remediated and rotated the credential the same day after disclosure via HackerOne.

vuln-research

Summary

Wiz Research's autonomous AI 'Red Agent' discovered a critical GitHub Actions script injection vulnerability in Snowflake's public snowflakedb/snowflake-connector-net repository during ongoing research conducted through Snowflake's HackerOne disclosure program. The flaw let an unauthenticated user execute arbitrary commands in a GitHub Actions runner simply by opening an issue with a maliciously crafted title.[0][1]

Notably, the vulnerable code was introduced only five days before discovery by an AI coding assistant: GitHub Copilot Autofix co-authored the June 18, 2026 commit (PR #1218) that removed the repository's existing sanitized input pattern and replaced it with direct string expansion of the attacker-controlled issue title in a shell script.[0][1]

Wiz's proof-of-concept exploited the flaw to break out of the shell echo string and exfiltrate a Jira credential via an out-of-band callback, gaining read access to Snowflake's engineering, security compliance, and bug bounty tracking projects. Snowflake patched the flaw the same day it was reported (June 23, 2026), rotated the token the next day, and confirmed via audit logs that Wiz was the sole third party to access the endpoint during the exposure window; Wiz deleted all accessed data.[0][1]

Attack chain

  1. Vulnerability introduction: GitHub Copilot Autofix co-authored a commit (4a1b8ce, PR #1218) on June 18, 2026 that replaced the repository's safe env-variable/jq input handling with direct interpolation of the attacker-controlled github.event.issue.title into a run: shell block.[0][1]
  2. Discovery: On June 23, 2026 Wiz Red Agent's CI/CD scanning capability scanned Snowflake's GitHub organization and flagged the jira_issue.yml workflow as vulnerable to script injection via untrusted input in run: blocks.[1]
  3. Exploitation: Wiz opened a GitHub issue with a specially crafted title; because sed escaping runs after GitHub template expansion, a single quote in the title broke out of the echo '...' string, achieving arbitrary command execution in the runner.[0][1]
  4. Credential exfiltration: The crafted title exfiltrated the workflow's Jira credentials via an out-of-band callback, giving read access to Snowflake's engineering, security compliance, and bug bounty tracking Jira projects.[0][1]

Disclosure timeline

DateEvent
2026-06-18Copilot Autofix co-authored commit 4a1b8ce (PR #1218) introducing the script injection vulnerability into jira_issue.yml.[0][1]
2026-06-23Wiz Red Agent discovered the vulnerability and responsibly disclosed it; Snowflake patched it the same day.[0][1]
2026-06-24Snowflake revoked and rotated the affected Jira token the day after disclosure.[0][1]

How it works

The jira_issue.yml GitHub Actions workflow triggered on 'issues: opened', so any GitHub user could invoke it by opening an issue. The workflow interpolated the attacker-controlled issue title directly into a shell run: block as TITLE=$(echo '${{ github.event.issue.title }}' | sed 's/"/\\"/g' | sed "s/'/\\\\'/g").[1]

Because GitHub template expansion of ${{ github.event.issue.title }} occurs before the sed escaping executes, a single quote placed in the issue title breaks out of the echo '...' quoting, enabling arbitrary command execution inside the runner. This regressed from the repository's prior safe pattern that passed the title through an env: variable and built the JSON payload with jq.[0][1]

Affected versions and patch status

ProductAffectedPatch status
snowflakedb/snowflake-connector-net (jira_issue.yml GitHub Actions workflow)Workflow state introduced by commit 4a1b8ce / PR #1218 on June 18, 2026Patched by Snowflake on June 23, 2026, the same day it was reported; affected Jira token revoked and rotated the following day.[0][1]

Key takeaways

  • AI coding assistants can silently reintroduce workflow injection vulnerabilities by replacing existing safe input-handling patterns with unsafe direct interpolation, as Copilot Autofix did here.[0][1]
  • Autonomous AI security agents can rapidly surface such flaws in the wild — Wiz's Red Agent found and exploited this bug within five days of its introduction — underscoring that human code review alone is insufficient in an AI-assisted development era.[0][1]
  • GitHub Actions workflows triggered by untrusted external input (like issue titles) that interpolate that input into shell commands are a recurring, high-impact injection risk that can lead to arbitrary command execution and credential theft.[0][1]

Defensive actions

  • Avoid direct interpolation of untrusted GitHub context (e.g. github.event.issue.title) into run: shell blocks; pass such values through env: variables and process them with tools like jq.: The vulnerability arose precisely because a safe env/jq pattern was replaced by direct string expansion, allowing attacker-controlled input to break out of shell quoting.[0][1]
  • Treat AI-coding-assistant-generated changes to CI/CD workflows as security-sensitive and subject them to review beyond ordinary human code review.: An AI assistant (Copilot Autofix) inadvertently introduced the injection, and Wiz notes human code review alone was insufficient to quickly detect the flaw as AI-generated code proliferates.[0][1]
  • Rotate any credentials (such as Jira tokens) exposed to workflows that can be triggered by untrusted external actors, and verify access via audit logs.: Snowflake rotated the exposed Jira token and used audit logs to confirm no unauthorized third party accessed the endpoint during the exposure window.[0][1]