Beta The Briev beta is out. Free on iPhone via TestFlight — install it in under a minute.

Join the beta ↗
Briev
Live
Technology

AI coding assistant injects bug into Snowflake connector, autonomous AI agent exploits it

A script-injection flaw added by an AI coding assistant to Snowflake’s.NET connector was automatically found and leveraged by Wiz’s autonomous red-agent, stealing credentials before Snowflake patched the issue through its bug-bounty program.

On June 18, GitHub Copilot Autofix co-authored a pull request that removed a sanitised input pattern in the snowflake-connector-net project, creating a script-injection vulnerability in the run: block of a GitHub Actions workflow. Five days later, Wiz’s autonomous red-agent, an AI-powered offensive security system, identified the flaw while scanning public repositories and generated a specially crafted issue title that broke out of an echo command, allowing arbitrary command execution on the Actions runner.

This breach exfiltrated a Jira credential, giving the agent read access to Snowflake’s engineering, security compliance, and bug-bounty tracking resources. Snowflake responded through its HackerOne bug-bounty program, patching the workflow on June 23 and rotating the compromised token the following day. Wiz confirmed it was the sole third-party to access the endpoint during the exposure window and deleted all retrieved data. The incident underscores how AI-assisted development can unintentionally embed critical vulnerabilities that autonomous AI attackers can swiftly exploit.

Why it matters

It shows how AI tools can create hidden security flaws that automated attackers can quickly weaponize.

In this story

AI coding assistantscript injection bugGitHub Actions workflowbug bountyautonomous AI attackercredential exfiltrationred agent
Get the beta ↗