{"data":{"id":"dd963b4b-044d-4c7f-8d68-ab3100b60753","title":"Wiz Red Agent Finds Its Way Into Snowflake’s Internal Jira Due to an AI-Generated GitHub Copilot “Autofix”","summary":"A security researcher's AI tool (Wiz Red Agent) found a critical vulnerability in Snowflake's GitHub workflow that allowed attackers to run arbitrary commands by opening a GitHub issue with a specially crafted title. The vulnerability was accidentally introduced five days earlier when GitHub Copilot's autofix feature removed safe input sanitization (a protective pattern using environment variables and jq, a JSON processor) and replaced it with direct string expansion, creating a script injection vulnerability (a flaw where untrusted input is directly inserted into executable code).","solution":"Upon responsible disclosure on June 23, 2026 by Wiz, Snowflake remediated the vulnerability on the same day, rotated the affected credential, and verified via detailed audit logs that Wiz was the sole actor during the exposure window.","labels":["security","research"],"sourceUrl":"https://www.wiz.io/blog/red-agent-snowflake-copilot-cicd-bug","publishedAt":"2026-08-17T14:00:00.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"high","attackType":["supply_chain"],"issueType":"news","affectedPackages":null,"affectedVendors":["Microsoft"],"affectedVendorsRaw":["Snowflake","GitHub","GitHub Copilot","Microsoft"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"patchAvailable":null,"disclosureDate":"2026-08-17T14:00:00.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"advanced","impactType":["integrity","confidentiality"],"aiComponentTargeted":"api","llmSpecific":false,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":null}}