DEV Community

Achin Bansal
Achin Bansal

Posted on Originally published at gridthegrey.com

GitHub Copilot Autofix Introduced CI/CD Injection in Snowflake

Forensic Summary

Wiz Research's autonomous Red Agent discovered and exploited a GitHub Actions script injection vulnerability in a Snowflake public repository, introduced by a GitHub Copilot Autofix co-authored commit just five days prior. The flaw allowed any unauthenticated GitHub user to execute arbitrary commands in a Actions runner by crafting a malicious issue title, ultimately enabling exfiltration of a token granting access to Snowflake's internal Jira instance. The incident exposes a critical trust gap: AI-assisted code review and AI-generated fixes can introduce and simultaneously fail to detect severe security vulnerabilities.


Read the full technical deep-dive on Grid the Grey: https://gridthegrey.com/posts/github-copilot-autofix-introduced-ci-cd-injection-in-snowflake/

Top comments (0)