Snowflake remediated a command-injection flaw in the public snowflakedb/snowflake-connector-net repository after Wiz showed that a crafted GitHub issue could trigger arbitrary command execution in a GitHub Actions runner. The vulnerable workflow, .github/workflows/jira_issue.yml, expanded attacker-controlled issue title and body fields directly inside a shell run block, allowing an unauthenticated attacker to open an issue and execute commands during CI/CD processing. Wiz reported receiving an out-of-band callback from the runner and recovering a Jira API token associated with qa@snowflake.net, which had read access to projects on snowflakecomputing.atlassian.net.
Reporting said the flaw was introduced in a June 18 commit co-authored by GitHub Copilot Autofix, which replaced a sanitized input pattern with direct string expansion in shell code. Snowflake patched the workflow on June 23, rotated the exposed Jira token on June 24, and said audit logs showed only Wiz accessed the endpoint during the roughly five-day exposure window, with no evidence of broader unauthorized use. The issue was confined to CI/CD automation, did not affect released Snowflake Connector for .NET packages, and highlights the continuing risk of GitHub Actions workflow injection when untrusted input is passed into shell commands without proper sanitization.

Trace attribution and downstream blast radius.
6 events from the most recent confirmed update back to the earliest known activity.
In a report published on August 17, Wiz said GitHub Advanced Security had analyzed the final revision of Snowflake's vulnerable pull request but did not flag the GitHub Actions injection flaw. The publication also detailed that Wiz's Red Agent autonomously discovered, exploited, and assessed the issue's blast radius.
After the report, Snowflake revoked and rotated the affected Jira API token tied to qa@snowflake.net. Snowflake later said its review found no unrelated external use of the token during the five-day exposure window.
Snowflake fixed the issue the same day it was reported, merging a remediation in pull request #1402. The fix replaced direct GitHub expression expansion with safer handling using environment variables passed to jq as arguments.
Wiz's Red Agent found the workflow injection vulnerability during authorized testing and reported it to Snowflake through HackerOne report #3819931. Wiz demonstrated that a crafted GitHub issue could execute commands in the Actions runner and exfiltrate a Jira API token with read access to multiple Snowflake Jira projects.
The vulnerable GitHub Actions workflow reached the repository's default branch when pull request #1218 was merged. This left the public issue-triggered workflow exposed to crafted issue input.
An unsafe refactor in the snowflakedb/snowflake-connector-net repository's .github/workflows/jira_issue.yml introduced direct expansion of attacker-controlled issue fields inside a shell run block. The available GitHub history cited by reporting attributes this change to commit 094038e.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
11 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecysecurity.news
Open sourceitpro.com
Open sourceinfosecurity-magazine.com
Open sourcetheregister.com
Open sourcewiz.io
Open sourcegithub.com
Open sourcegithub.blog
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.