Wiz Red Agent Finds Its Way Into Snowflake’s Internal Jira Through a Flaw in a GitHub Copilot–Assisted PR
ID: 8e5169b8-3596-5e46-b145-3086c5bda606
STIX ID: report--8e5169b8-3596-5e46-b145-3086c5bda606
Feed Name: Wiz Blog
Threat Score
Wiz Research's autonomous Red Agent discovered a critical script-injection vulnerability in Snowflake's public GitHub Actions workflow that interpolated untrusted issue titles into shell commands, enabling remote command execution and exfiltration of a Jira API token; Snowflake patched the workflow and rotated the credential the same day after responsible disclosure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
