news.mlab.sh
Back to the feed
vulnerability

Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection

Medium
Image: The Hacker News
Summary

Researchers at Wiz discovered a GitHub Actions workflow injection vulnerability in Snowflake's snowflakedb/snowflake-connector-net repository. An attacker could craft a GitHub issue to inject malicious code into a workflow, potentially exposing Jira credentials and gaining access to Snowflake Jira projects. Snowflake patched the issue on June 23, 2026, after Wiz reported the vulnerability.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.