AI 编程 4.0 · 优秀 2026-08-17 · 文章

Red Agent Exploits Snowflake Vuln Missed by GitHub Copilot

Wiz 的自主安全研究 agent 'Red Agent' 通过 Snowflake 的 HackerOne 项目发现 snowflake-connector-net 仓库的 GitHub Actions 脚本注入漏洞:任何未认证用户开一个标题经构造的 issue,即可在 Actions runner 内执行任意命令注入模式随 2026-06-18 合并的 PR #1218 上线Copilot 作为 co-author 检查过合并后变更并给出 all-clear,GitHub Advanced Security 扫描同样未标记...

打开原文回到归档

Red Agent Exploits Snowflake Vuln Missed by Github Copilot

中文导读

Wiz 的自主安全研究 agent 'Red Agent' 通过 Snowflake 的 HackerOne 项目发现 snowflake-connector-net 仓库的 GitHub Actions 脚本注入漏洞:任何未认证用户开一个标题经构造的 issue,即可在 Actions runner 内执行任意命令注入模式随 2026-06-18 合并的 PR #1218 上线Copilot 作为 co-author 检查过合并后变更并给出 all-clear,GitHub Advanced Security 扫描同样未标记;Red Agent 在漏洞上线五天内发现并完成利用(经外泄 token 进入 Snowflake 的 Jira 门户)6 月 23 日负责任披露当天 Snowflake 完成修复轮换凭据并经审计日志确认暴露窗口内唯一操作者是 Wiz攻防不对称的现实样本:AI 编码 agent 参与引入的漏洞能通过既有自动安全检查,而自主安全 agent 已能在野外快速发现并利用

为什么值得关注

Red Agent 五天攻破 Snowflake CI/CD:Copilot 审查为 all-clear 的 Actions 注入漏洞被自主安全 agent 发现并利用

Excerpt (English)

作者: https://www.wiz.io/authors/gal-nagli
发布时间: 2026-08-17T10:00:00-04:00
原文链接: https://www.wiz.io/blog/red-agent-snowflake-copilot-cicd-bug

As part of ongoing security research conducted through Snowflake’s HackerOne vulnerability disclosure program, Wiz Research’s "Red Agent"—an autonomous, AI-powered security research tool—identified a critical GitHub Actions workflow vulnerability in one of Snowflake’s public repositories.

This incident highlights a new reality in software development: Critical vulnerabilities can still be introduced and approved within workflows involving AI coding agents and can still pass established automated security checks, while autonomous AI security agents can rapidly discover and exploit them in the wild.

Upon responsible disclosure on June 23, 2026 by Wiz, Snowflake remediated the vulnerability on the same day, rotated the affected credential, and verified via detailed audit logs that Wiz was the sole actor during the exposure window. Wiz confirmed that all data accessed during proof-of-concept testing was securely deleted.

_August 17, 2026, 1957 UTC update: This blog has been updated to clarify that Copilot was a co-author that checked the merged PR and code change, and identified it as all-clear without noticing the critical vulnerabilities. It's unclear whether the code-change was AI-assisted._

Executive Summary

Wiz Red Agent identified a script injection vulnerability in snowflakedb/snowflake-connector-net. The issue allowed an unauthenticated user to execute arbitrary commands within a GitHub Actions runner by opening a GitHub issue with a specially crafted title.

Crucially, the vulnerability became live on June 18, 2026 - just five days before its discovery - when PR #1218 was merged. GitHub Advanced Security scan analyzed the final PR revision, including the vulnerable workflow, but did not flag the critical injection.

Screenshot demonstrating access to Snowflake's Jira portal, via an exfiltrated token

Exposure Walk-Through

Discovery

Wiz Red Agent's CI/CD capability scanned Snowflake's GitHub organization and flagged the `jira_issue.yml` Workflow in `snowflakedb/snowflake-connector-net` as vulnerable to script injection via untrusted input in run: blocks.

The Code Change


- env:

- ISSUE_TITLE: ${{ github.event.issue.title }}

- run: jq -n --arg title "$ISSUE_TITLE" ...

+ run: TITLE=$(echo '${{ github.event.issue.title }}' | sed ...)

Obsidian Notes

  • 内容由 opencli web read 拉取原文生成,导读锚定在条目已有摘要与原文可见正文。