www.infosecurity-magazine.com 8/18/2026, 3:58:12 PM · external

Wiz AI finds Snowflake connector flaw missed by GitHub security

Wiz AI finds Snowflake connector flaw missed by GitHub security
CyberSIXT Evidence Panel
Primary Source wiz.io

RESEARCHERS from Wiz, a part of Google Cloud, identified a critical script injection vulnerability in a public GitHub repository for Snowflake's connector. This vulnerability, which went unnoticed by GitHub's Advanced Security, allows unauthenticated users to execute commands via GitHub Actions. Wiz's AI-powered tool, Red Agent, discovered and exploited the flaw, validating access to sensitive data without human intervention. Snowflake was promptly notified, patched the issue, and rotated their Jira access token, claiming no evidence of unauthorized data access was found.

View Primary Source Via www.infosecurity-magazine.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline