importantSYS.SOURCE: The Hacker News• 2026-08-18T00:14:17+05:30
Snowflake GitHub Actions Vulnerability Allows Command Injection via Crafted Issues
A GitHub Actions workflow vulnerability in Snowflake's repository allowed command injection via crafted issues, exposing Jira credentials. The flaw was patched, and no unauthorized access was confirmed.
Cybersecurity researchers at Wiz have disclosed a new GitHub Actions workflow injection vulnerability in Snowflake's public snowflakedb/snowflake-connector-net repository that it said could be exploited through a crafted GitHub issue to execute commands in a workflow containing internal Jira credentials.
The issue was present in .github/workflows/jira_issue.yml, which ran when a
*** END OF TRANSMISSION ***