Snowflake flaw slips past AI checks, gets exploited by another AI
Summary
GitHub Copilot failed to catch a critical vulnerability in Snowflake's code during a review, but an autonomous AI security agent called Red Agent developed by Wiz successfully identified and exploited the flaw. The vulnerability was a command injection (allowing attackers to insert malicious commands into a workflow) in Snowflake's GitHub Actions pipeline that let attackers access internal Jira credentials, though Snowflake patched it the same day it was reported and found no evidence of unauthorized access.
Solution / Mitigation
Snowflake patched the workflow on June 23 by restoring the safer input-handling pattern and rotated the affected Jira credential the following day.
Classification
Affected Vendors
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://www.csoonline.com/article/4211501/snowflake-flaw-slips-past-ai-checks-gets-exploited-by-another-ai.html
First tracked: August 19, 2026 at 08:01 AM
Classified by LLM (prompt v3) · confidence: 85%