THREATOPS
THREAT OPSThreat News › Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection

Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection

lowthehackernewsPublished 2026-08-17

Cybersecurity researchers at Wiz have disclosed a new GitHub Actions workflow injection vulnerability in Snowflake's public snowflakedb/snowflake-connector-net repository that it said could be exploited through a crafted GitHub issue to execute commands in a workflow containing internal Jira credentials.

The issue was present in .github/workflows/jira_issue.yml, which ran when a

MITRE ATT&CK techniques

Original source: https://thehackernews.com/2026/08/snowflake-github-actions-flaw-lets_0330881554.html