{"data":{"id":"d827573e-55a6-47b9-aa94-e26195f085ee","title":"CVE-2026-19594: Insufficient input sanitization in Snowflake Python API (`snowflake.core`) versions prior to 1.13.0 allowed confused-dep","summary":"A vulnerability in Snowflake Python API (a library for connecting to Snowflake databases) versions before 1.13.0 allowed attackers to bypass security restrictions through two methods: path traversal (using `..` to access parent resources) and HTTP parameter pollution (injecting special characters like `&`, `#`, `=` to change how requests are interpreted). An attacker who could control certain input values in an application using this library could trick it into executing privileged operations under a higher-permission user account.","solution":"\"The fix is available in Snowflake Python API version 1.13.0, which also addresses several additional security findings. Users must manually upgrade.\"","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-19594","publishedAt":"2026-08-12T06:21:57.223Z","cveId":"CVE-2026-19594","cweIds":["CWE-22","CWE-141"],"cvssScore":"8.1","cvssSeverity":"high","severity":"high","attackType":["supply_chain"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["Snowflake"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","attackVector":"network","attackComplexity":"low","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-08-12T06:21:57.223Z","capecIds":["CAPEC-126"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity","confidentiality"],"aiComponentTargeted":null,"llmSpecific":false,"classifierConfidence":0.72,"researchCategory":null,"atlasIds":["AML.T0010"]}}