Intelligence
AEV-2026-0005

Autonomous agent found and exploited a GitHub Actions injection in a Snowflake repository

Wiz's autonomous Red Agent found a GitHub Actions script injection in snowflakedb/snowflake-connector-net, exploited it through a runtime chain of individually permitted steps, and exfiltrated Jira credentials, all without human intervention. Sanctioned research under Snowflake's bug bounty; patched the same day and the token rotated.

AESS 6.9 mediumConfirmedStatus: resolvedEvent: 17 August 2026Sequence IntegrityExecution AuthorityAgent Identity

Affected

Organisation
Snowflake
Product
snowflakedb/snowflake-connector-net GitHub Actions workflow
Component
A workflow that interpolated an issue title directly into a shell command
Versions
The workflow state introduced by PR 1218 on 18 June 2026; fixed 23 June 2026
Configurations
Issue title interpolated into a shell command without safe handling

Execution authority facts

Fields the evidence does not establish are shown as unknown rather than guessed.

Intended task
An autonomous security agent scanning a public GitHub organisation
Agent
Wiz Red Agent
Delegating actor
Wiz, under Snowflake's HackerOne programme
Action
Identified the injectable workflow, adapted after a first payload error, exploited it and exfiltrated Jira credentials via an out of band callback
Target resource
The GitHub Actions runner and, through it, Snowflake's Jira
Environment
Snowflake's public GitHub organisation and CI
Credentials used
Jira credentials exposed to the workflow
Privileges available
Read access across engineering, security compliance and bug bounty Jira projects
Authority presented
The access of the injectable CI workflow
Authority required
Authority to read Snowflake's internal Jira
Applicable policy
unknown
Approval mechanism
unknown
Required approver
unknown
Independent approval
unknown
Action binding
unknown
Sequence context
A runtime chain: scan, identify, fail, re approach, exploit, exfiltrate, confirm access, assess blast radius

Impact

Consequence
Jira credentials exfiltrated and read access confirmed across internal projects
Reach
Snowflake's internal Jira across several projects
Reversibility
Recovered: patched the same day and the Jira token rotated, with logs showing no unauthorized access beyond Wiz test infrastructure
Detectability
Delayed: found by the agent five days after the vulnerable change merged
Propagation
No propagation beyond the assessed blast radius
Recovery
Same day patch and token rotation

Evidence

Primary sources

Supporting sources

Reproduction status
Executed by Wiz as sanctioned research; confirmed by Snowflake's remediation
Evidence state
Confirmed

Known unknowns

  • Whether the vulnerable code change was itself AI assisted, which Wiz later said is unclear.

Limitations

  • This was authorised research under a bug bounty; no malicious exploitation occurred.

Claim provenance