Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection Emmie Evans August 18, 2026

Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection

Cybersecurity researchers at Wiz have disclosed a new GitHub Actions workflow injection vulnerability in Snowflake’s public snowflakedb/snowflake-connector-net repository that it said could be exploited through a crafted GitHub issue to execute commands in a workflow containing internal Jira credentials.

The issue was present in .github/workflows/jira_issue.yml, which ran when a

Write a comment
Your email address will not be published. Required fields are marked *
Scroll to Top