Wiz disclosed a GitHub Actions workflow injection flaw in Snowflake’s public snowflakedb/snowflake-connector-net repository that could let a crafted GitHub issue trigger commands and expose Jira credentials in the CI/CD workflow. Snowflake fixed the issue the same day it was reported, and the available evidence shows authorized testing only, with no confirmed unauthorized access. #Snowflake #Wiz #GitHubActions #snowflakedb/snowflake-connector-net #Jira
Keypoints
- A workflow injection flaw was found in Snowflake’s public GitHub repository.
- Attackers could abuse a crafted GitHub issue to execute commands in the workflow.
- The vulnerable workflow exposed Jira credentials, including a Jira API token.
- Wiz said it used the flaw during authorized security testing and obtained a callback.
- Snowflake patched the issue and reported no evidence of unauthorized access.
Read More: https://thehackernews.com/2026/08/snowflake-github-actions-flaw-lets_0330881554.html