{"id":2382,"date":"2026-08-17T19:57:01","date_gmt":"2026-08-17T19:57:01","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=2382"},"modified":"2026-08-17T19:57:01","modified_gmt":"2026-08-17T19:57:01","slug":"snowflake-github-actions-flaw-lets-crafted-issues-trigger-command-injection","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=2382","title":{"rendered":"Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Swati Khandelwal<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Aug 17, 2026<\/span><\/span><span class=\"p-tags\">Vulnerability \/ Artificial Intelligence<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgJW5BJKjwNfnH2t8RrvgW0wUO3_ZJWnw30aS6GlU9qoaOWMQcyoZ9ZOZmTgLo7hWAqHlKDK2b4MrtF23Jv_1-1Ffd6bo6VlR8exLvIISBANwjHnW3dv7wLgCtyCIDlndpJ67TajeEpN-Ww9eVVutmS4fTpcDPJtlAk_ZU0GLtnkDvYLlqWPv75uMH7ob__\/s1700-e365\/snowflake.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Cybersecurity researchers at Wiz have disclosed a new GitHub Actions workflow injection vulnerability in Snowflake&#8217;s public <a href=\"https:\/\/github.com\/snowflakedb\/snowflake-connector-net\" target=\"_blank\">snowflakedb\/snowflake-connector-net<\/a> repository that it said could be exploited through a crafted GitHub issue to execute commands in a workflow containing internal Jira credentials.<\/p>\n<p>The issue was present in <a href=\"https:\/\/github.com\/snowflakedb\/snowflake-connector-net\/blob\/4a1b8cecd65b899540e4324715557d6b080ddeb5\/.github\/workflows\/jira_issue.yml\" target=\"_blank\">.github\/workflows\/jira_issue.yml<\/a>, which ran when a public issue was opened and exposed JIRA_BASE_URL, JIRA_USER_EMAIL, and JIRA_API_TOKEN to the same workflow step. The weakness was confined to the repository&#8217;s CI\/CD automation, with no affected Snowflake Connector for .NET release identified.<\/p>\n<p>The workflow inserted attacker-controlled issue title and body values directly into a shell run: block. It also checked github.event.pull_request.user.login even though the event was an issue, meaning the referenced pull request property did not exist.<\/p>\n<p><a href=\"https:\/\/docs.github.com\/en\/actions\/reference\/workflows-and-actions\/contexts\" target=\"_blank\">GitHub says<\/a>, \u00abIf you attempt to dereference a nonexistent property, it will evaluate to an empty string.\u00bb In this case, the comparison against whitesource-for-github-com[bot] did not stop an ordinary issue from reaching the job.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/zero-trust-claude-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj8iAp2j8rqTq6aptj6yiYHC-B73UxnWI2NQMt0azp6OVLq9JkO8cpYokLWa8t_IKqrHKPsaM5D_lQ9Ip7kZTi3at4oYfzN1m1b_T4b6MuzBWtmlhdLcQ0nZHicD94rliREFDRewsKBQCTYrAAVNzYKj84_0EZskDUxvkc972s9fYAqcQGEQjVZTc0cr7TB\/s728-e100\/ThreatLocker-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Wiz <a href=\"https:\/\/www.wiz.io\/blog\/red-agent-snowflake-copilot-cicd-bug\" target=\"_blank\">said<\/a> its Red Agent system exploited the injection during authorized security testing after the first payload resulted in a shell syntax error and the system changed its approach. The researchers said they subsequently received an out-of-band callback from the GitHub Actions runner and obtained the Jira API token used by the workflow.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>The token, according to Wiz, belonged to qa@snowflake.net and allowed read access to Jira projects covering engineering, security compliance, and bug bounty tracking on snowflakecomputing.atlassian.net. The underlying Jira permissions, workflow run, and audit records are not public.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh1e6rDEmjXWfr6jjXEHc8iH-LGkFKO36VVym4Dcjs9I9HWWmcEc4msFS6quNV93gzqLXfeMbsJtgZRMRAY7qOxT698AJxX9kclzAMRNw8tIjdqRIZ6Yf_JwL4Jh8sfGYzLdQW-VyObHOdtXSP2as1oQVoUs67h1h99BGDdrjCuMjGyUvXx3Ts5Lxf3gyxA\/s1700-e365\/comment.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh1e6rDEmjXWfr6jjXEHc8iH-LGkFKO36VVym4Dcjs9I9HWWmcEc4msFS6quNV93gzqLXfeMbsJtgZRMRAY7qOxT698AJxX9kclzAMRNw8tIjdqRIZ6Yf_JwL4Jh8sfGYzLdQW-VyObHOdtXSP2as1oQVoUs67h1h99BGDdrjCuMjGyUvXx3Ts5Lxf3gyxA\/s1700-e365\/comment.jpg\" alt=\"\" border=\"0\" data-original-height=\"1051\" data-original-width=\"2048\"\/><\/a><\/div>\n<p>Wiz said it reported the issue to Snowflake through HackerOne on June 23, 2026, under report #3819931. Snowflake merged a fix that day in <a href=\"https:\/\/github.com\/snowflakedb\/snowflake-connector-net\/pull\/1402\" target=\"_blank\">pull request #1402<\/a>, replacing the direct GitHub expression expansion with environment variables that are passed to jq as arguments.<\/p>\n<p>The vulnerable workflow had reached the default branch five days earlier, on June 18, when <a href=\"https:\/\/github.com\/snowflakedb\/snowflake-connector-net\/pull\/1218\" target=\"_blank\">pull request #1218<\/a> was merged. The corrected handling remains in the repository&#8217;s <a href=\"https:\/\/github.com\/snowflakedb\/snowflake-connector-net\/blob\/master\/.github\/workflows\/jira_issue.yml\" target=\"_blank\">master branch<\/a>.<\/p>\n<p>Snowflake said in a statement reproduced by Wiz that \u00abour investigation found no evidence of unauthorized access.\u00bb Wiz said the Jira token was rotated on June 24 and that Snowflake&#8217;s review found no unrelated external use of it during the five-day exposure window. Snowflake&#8217;s underlying audit logs have not been made public.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjYuPX6yhUhVIH8mkaqGF-kxLLo2HJqOuYTQeLDYTCu8hzVVaNxfSjMcg_VLaT5woKdPnGadBRanIQJD9HZkrxNV6rXpTNxIc-XWf0u6yri82ocCjDEVg14HFDG8hvMxJZa8vvBgglgOKKiKwi307c2NJyo90WmCoHis3WrFepopBOVkI-qISbJoxX-4bO-\/s1700-e365\/jira.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjYuPX6yhUhVIH8mkaqGF-kxLLo2HJqOuYTQeLDYTCu8hzVVaNxfSjMcg_VLaT5woKdPnGadBRanIQJD9HZkrxNV6rXpTNxIc-XWf0u6yri82ocCjDEVg14HFDG8hvMxJZa8vvBgglgOKKiKwi307c2NJyo90WmCoHis3WrFepopBOVkI-qISbJoxX-4bO-\/s1700-e365\/jira.jpg\" alt=\"\" border=\"0\" data-original-height=\"768\" data-original-width=\"1173\"\/><\/a><\/div>\n<p>Wiz described the flaw as resulting from a GitHub Copilot Autofix change, although the underlying GitHub history does not establish Copilot as the author of the vulnerable jira_issue.yml code. The explicit Copilot co-authored commit, <a href=\"https:\/\/github.com\/snowflakedb\/snowflake-connector-net\/pull\/1218\/commits\/6d0e2fa1d644d04e036b9afa69513aa0c0c83132\" target=\"_blank\">6d0e2fa<\/a>, changed jira_close.yml, while the unsafe jira_issue.yml refactor appears in a separate August 25, 2025, commit, <a href=\"https:\/\/github.com\/snowflakedb\/snowflake-connector-net\/pull\/1218\/commits\/094038e59d112906f1790acf39999045fc0df243\" target=\"_blank\">094038e<\/a>, attributed by GitHub to sfc-gh-hpathak.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/corelight-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjuvAqH13TTYyJD3aI-pJcYl54BoxQWMHc2aFwW2HbYUa5IKCjvHlzpzkFwXLTuV8aytky8kqLBgkoOtC8VQM5CGR0N5BXBl8RSXl-PYx_vIPbiLywiqXIvTPmm18cdEm_C0heVB-3U8zfG7K27RCAurtJ7OvxEyfQ0sVV_RRx1N4ZMWkqKgEBmkcDgjD6I\/s728-e100\/code-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Both changes were later folded into the June 18 squash merge commit <a href=\"https:\/\/github.com\/snowflakedb\/snowflake-connector-net\/commit\/4a1b8cecd65b899540e4324715557d6b080ddeb5\" target=\"_blank\">4a1b8ce<\/a>, which lists Copilot Autofix among its co-authors. The commit history therefore confirms Copilot participation in pull request #1218, but not authorship of the vulnerable lines.<\/p>\n<p><a href=\"https:\/\/github.blog\/security\/vulnerability-research\/how-to-catch-github-actions-workflow-injections-before-attackers-do\/\" target=\"_blank\">GitHub had documented this class of workflow injection in July 2025<\/a>, warning against expanding untrusted issue data directly inside run: blocks and recommending the use of intermediate environment variables.<\/p>\n<p>As of August 17, 2026, no CVE, CVSS score, or CISA Known Exploited Vulnerabilities (KEV) catalog entry had been located for the issue, and no connector release update tied to it had been identified. The vulnerable interpolation is no longer present on master, and the available primary material does not establish malicious exploitation in the wild or customer compromise.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Swati Khandelwal\ue802Aug 17, 2026Vulnerability \/ Artificial Intelligence Cybersecurity researchers at Wiz have disclosed a new GitHub Actions workflow injection vulnerability in Snowflake&#8217;s public snowflakedb\/snowflake-connector-net repository that it said could be&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2383,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[802,1223,1684,70,71,525,517,332,2906,2258],"class_list":["post-2382","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-actions","tag-command","tag-crafted","tag-flaw","tag-github","tag-injection","tag-issues","tag-lets","tag-snowflake","tag-trigger"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2382","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2382"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2382\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/2383"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2382"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2382"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2382"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}