Security researchers at Wiz have identified a critical script injection vulnerability within a public Snowflake repository on GitHub, revealing a significant blind spot in automated security tooling. The flaw, which resided in the snowflakedb/snowflake-connector-net repository, was discovered by Wiz Research’s autonomous AI agent, known as Red Agent.
According to the technical report released by Gal Nagli, head of threat exposure at Wiz Research, the vulnerability was introduced on June 18, 2026, following the merge of pull request #1218. The flaw allowed unauthenticated users to execute arbitrary commands within a GitHub Actions runner simply by creating a GitHub issue with a specially crafted title. Despite the implementation of GitHub Advanced Security—which utilizes GitHub Copilot Autofix—the vulnerability remained undetected during the code review process.
The Wiz Red Agent identified the issue on June 23 as part of a broader security assessment conducted through Snowflake’s HackerOne vulnerability disclosure program. The AI agent performed an end-to-end analysis: it discovered the injection, validated the potential for command execution, and assessed the impact on Snowflake’s internal Jira connector without human intervention.
Snowflake responded immediately upon notification on June 23. The company patched the vulnerable workflow through PR #1402 and rotated the affected Jira token on June 24. In a statement, Snowflake confirmed that its internal investigation found no evidence of unauthorized access to its systems. Both organizations are now collaborating to document these findings to help the industry improve security practices regarding GitHub Actions configurations.
Follow-up Questions
Why did GitHub Advanced Security fail to detect the injection?
While the specific technical reason for the failure remains proprietary to GitHub's scanning logic, Wiz noted that automated tools often struggle with complex workflow configurations, highlighting the need for AI-driven research to complement standard static analysis
Is this vulnerability limited to Snowflake?
No. The vulnerability class—GitHub Actions injection—is a broader industry concern. The collaboration between Wiz and Snowflake aims to educate other organizations on securing their CI/CD pipelines against similar automated bypasses
Perspectives
Wiz Research View vs Industry/Developer View
Story lens
Wiz Research View
Wiz positions its autonomous Red Agent as a necessary evolution in cybersecurity, arguing that human-led research and standard static analysis tools are no longer sufficient for modern, complex cloud environments. By automating the discovery and validation process, they demonstrate that AI can identify flaws that bypass traditional 'shift-left' security gates
Industry/Developer View
The incident signals a growing concern regarding the reliability of automated CI/CD security tools. Developers are reminded that while tools like GitHub Advanced Security are essential, they are not infallible, necessitating a defense-in-depth strategy that includes periodic third-party or AI-assisted security audits
A high-stakes federal trial in Oakland accuses Meta of designing addictive social media features that prioritize profit over the mental health of minors.
While Florida officials address crucial military-civilian traffic bottlenecks on Highway 98, Ohio commuters face extensive construction delays through 2028.
An autonomous AI agent from Wiz discovered a critical script injection flaw in a Snowflake GitHub repository that evaded GitHub Advanced Security detection.
A political clash erupted after Sen. Jon Ossoff questioned President Trump’s focus, drawing a personal retort from the President regarding his aide, Natalie Harp.