Skip to content

AI-Generated GitHub Copilot “Autofix” Allowed Compromise of Snowflake's Jira

8.5 relevance
Score Breakdown
technical depth
8
novelty
9
actionability
8
community
9
strategic
9
personal
9

Scored daily by a customisable AI persona to surface the most relevant engineering leadership news.

Critical security analysis of AI-generated Copilot autofix leading to Snowflake Jira compromise, highly relevant to AI in SDLC and security.

AI/ML wiz.io
AI-Generated GitHub Copilot “Autofix” Allowed Compromise of Snowflake's Jira
Summary

Wiz Research's autonomous AI agent, Red Agent, discovered a critical script injection vulnerability in Snowflake's GitHub Actions workflow that allowed arbitrary command execution via a crafted issue title. The vulnerable code was introduced by a PR that included an AI-generated Copilot Autofix, which GitHub Advanced Security scanned but failed to flag the injection. The flaw, live for five days before discovery, enabled exfiltration of Jira credentials and access to Snowflake's internal systems.

Author

Gal Nagli

More from Gal Nagli →