Particle.news

Snowflake Workflow Flaw Let Issue Titles Run Commands and Expose Jira Token

The incident shows how AI-assisted code changes can reintroduce unsafe patterns and how fast automated scanners compress the window for discovery and response.

Overview

  • Wiz’s autonomous Red Agent found and exploited a script-injection bug in the snowflakedb/snowflake-connector-net GitHub Actions jira_issue.yml workflow that interpolated issue title text directly into a shell run block.
  • The vulnerable change reached the default branch on June 18, 2026 and Wiz reported the flaw on June 23, 2026, after which Snowflake patched the workflow the same day and rotated the exposed Jira API token on June 24, 2026.
  • During authorized testing Wiz adapted its payload after an initial syntax error and received an out‑of‑band callback containing a base64 token that authenticated as qa@snowflake.net and allowed read access to several internal Jira projects.
  • Snowflake and Wiz say forensic logs attribute activity during the five‑day exposure window to Wiz’s testing IPs, no public evidence of external malicious use has emerged, and the vulnerable interpolation is removed from master.
  • The event highlights two industry issues: AI code assistants can unintentionally reintroduce insecure patterns in CI/CD, and rapid automated discovery increases the need for short‑lived credentials, stricter workflow guardrails, and fast incident response.