An AI broke Snowflake's code. Then another AI agent exploited it
Don't worry, this one was via a bug bounty program
An AI accidentally introduced a script injection vulnerability into Snowflake's code, which later allowed another AI-powered attack agent to exploit it and extract credentials without human involvement. The flaw, discovered on June 23, existed in the GitHub Actions workflow of snowflakedb/snowflake-connector-net repository. The vulnerability enabled an unauthenticated user to execute arbitrary commands within a GitHub Actions runner by creating a specially crafted issue title.
This issue was initially introduced by GitHub Copilot Autofix, an AI coding assistant, on June 18. Wiz, a cybersecurity firm, reported the vulnerability to Snowflake on June 23. Snowflake patched the flaw the same day and revoked and rotated the affected Jira credentials the following day. Wiz's investigation confirmed that no unauthorized access occurred, and they had been the only third-party to access the endpoint during the five-day exposure window.
The incident highlights the growing concern that AI coding assistants can inadvertently introduce vulnerabilities, and automated AI agents can quickly discover them in the wild, suggesting that human code review is insufficient for quickly detecting vulnerabilities, especially with the increasing use of AI in software development.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.
- An AI broke Snowflake's code. Then another AI agent exploited it theregister.com