ixsoftum
AI-assisted development

An AI coding tool introduced a bug in Snowflake's code. An AI agent found and exploited it

Published 17 Aug 2026, 19:03 UTC
Ava Harlan
Ava HarlanStaff writer
Share
An AI coding tool introduced a bug in Snowflake's code. An AI agent found and exploited it

A script-injection bug in a GitHub Actions workflow for Snowflake's snowflake-connector-net repository traces back to a commit GitHub Copilot Autofix co-authored on June 18, 2026. The change stripped out existing input sanitization and replaced it with direct string expansion, letting an unauthenticated user run arbitrary shell commands by crafting a specially formatted GitHub issue title.

Five days later, an autonomous offensive-security agent built by Wiz found the flaw during a routine scan and exploited it as part of a bug bounty submission. Wiz's proof of concept exfiltrated Jira credentials that granted read access to Snowflake's engineering, security-compliance, and bug-bounty tracking projects. Snowflake patched the workflow the same day the flaw was reported and rotated the affected Jira credentials the following day.

Snowflake says the incident was investigated and remediated immediately, with no evidence of unauthorized access beyond Wiz's own research. Audit logs show Wiz was the only third party to touch the exposed data during the five-day exposure window, and Wiz deleted everything it collected once the research wrapped.

The sequence is a preview of what AI-assisted development means for code review specifically. An automated fix quietly weakened a security control in a way that passed review, and an autonomous agent independently found and proved out the resulting exploit path in days. Both halves of that, the failure mode and the discovery method, are now automatable, which means automated fixes touching input handling or shell execution need the same scrutiny a human-authored PR would get, not less.