AEV-2026-0005
Autonomous agent found and exploited a GitHub Actions injection in a Snowflake repository
Wiz's autonomous Red Agent found a GitHub Actions script injection in snowflakedb/snowflake-connector-net, exploited it through a runtime chain of individually permitted steps, and exfiltrated Jira credentials, all without human intervention. Sanctioned research under Snowflake's bug bounty; patched the same day and the token rotated.
Affected
- Organisation
- Snowflake
- Product
- snowflakedb/snowflake-connector-net GitHub Actions workflow
- Component
- A workflow that interpolated an issue title directly into a shell command
- Versions
- The workflow state introduced by PR 1218 on 18 June 2026; fixed 23 June 2026
- Configurations
- Issue title interpolated into a shell command without safe handling
Execution authority facts
Fields the evidence does not establish are shown as unknown rather than guessed.
- Intended task
- An autonomous security agent scanning a public GitHub organisation
- Agent
- Wiz Red Agent
- Delegating actor
- Wiz, under Snowflake's HackerOne programme
- Action
- Identified the injectable workflow, adapted after a first payload error, exploited it and exfiltrated Jira credentials via an out of band callback
- Target resource
- The GitHub Actions runner and, through it, Snowflake's Jira
- Environment
- Snowflake's public GitHub organisation and CI
- Credentials used
- Jira credentials exposed to the workflow
- Privileges available
- Read access across engineering, security compliance and bug bounty Jira projects
- Authority presented
- The access of the injectable CI workflow
- Authority required
- Authority to read Snowflake's internal Jira
- Applicable policy
- unknown
- Approval mechanism
- unknown
- Required approver
- unknown
- Independent approval
- unknown
- Action binding
- unknown
- Sequence context
- A runtime chain: scan, identify, fail, re approach, exploit, exfiltrate, confirm access, assess blast radius
Impact
- Consequence
- Jira credentials exfiltrated and read access confirmed across internal projects
- Reach
- Snowflake's internal Jira across several projects
- Reversibility
- Recovered: patched the same day and the Jira token rotated, with logs showing no unauthorized access beyond Wiz test infrastructure
- Detectability
- Delayed: found by the agent five days after the vulnerable change merged
- Propagation
- No propagation beyond the assessed blast radius
- Recovery
- Same day patch and token rotation
Evidence
Primary sources
- Wiz Red Agent Finds Its Way Into Snowflake's Internal Jira Through a Flaw in a GitHub Copilot Assisted PR (Wiz)
- PR 1218: SNOW-2069227 : Update jira workflows (GitHub, snowflakedb/snowflake-connector-net)
Supporting sources
- Reproduction status
- Executed by Wiz as sanctioned research; confirmed by Snowflake's remediation
- Evidence state
- Confirmed
Known unknowns
- Whether the vulnerable code change was itself AI assisted, which Wiz later said is unclear.
Limitations
- This was authorised research under a bug bounty; no malicious exploitation occurred.
Claim provenance
- verified
Wiz's own write up describes the autonomous find and exploit chain; the GitHub PR and commits are primary artifacts.
The AI Review Missed the Bug. Five Days Later, Another Agent Exploited It.
