Copilot Autofix Opened a Shell Injection in Snowflake’s CI/CD Pipeline
Unite.AI
Read full postGitHub's Copilot Autofix introduced a security flaw in Snowflake's CI/CD pipeline by removing input sanitization in a GitHub Actions workflow. This allowed an autonomous AI agent to exploit the vulnerability and extract Jira credentials. Snowflake patched the issue within five days and rotated the compromised credentials.



