AI-Generated GitHub Copilot "Autofix" Allowed Compromise of Snowflake's Jira
Covered by 4 sources
Read full postWiz Research's AI-powered Red Agent discovered a critical script injection vulnerability in Snowflake's GitHub Actions workflow, introduced by a GitHub Copilot Autofix AI commit. The flaw allowed unauthenticated users to execute commands via issue titles, leading to potential Jira access. Snowflake patched the issue and rotated credentials promptly after disclosure on June 23, 2026.



