Urgent.News

What's breaking now, across thousands of outlets.

AI

AI-Generated GitHub Copilot “Autofix” Allowed Compromise of Snowflake's Jira

Wiz Research's autonomous AI tool, Red Agent, uncovered a critical GitHub Actions workflow vulnerability in Snowflake's public repository. On June 18, 2026, PR #1218 was merged and credited Copilot Autofix powered by AI as a co-author. The merge replaced the repository's sanitized input pattern with direct string expansion, creating an injection vector.

The workflow was triggered by any GitHub user opening an issue, allowing arbitrary command execution via the interpolated issue title. Snowflake patched the workflow and revoked the compromised JIRA token on June 23, 2026. This incident underscores the need for rigorous oversight of AI code generation in software development, as AI-generated PRs must undergo the same scrutiny as human-written code.

The vulnerability was live for just five days before being discovered and validated by the automated Red Agent.

Written by urgent.news from Hacker News's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at wiz.io →

More in AI

More from Monday 17 August →