- Sources: Wiz Research, HN discussion
- Summary: Wiz Research reports that an autonomous agent it operates found a shell-injection flaw in a GitHub Actions workflow in a Snowflake repository, and that the flaw was introduced by a GitHub Copilot Autofix commit which replaced an input-handling pattern that existed to prevent injection. Wiz reports the injection was reachable by any user who could open an issue, and that the disclosed chain reached read access to Snowflake's internal Jira. Wiz reports Snowflake patched the workflow on 2026-06-23 and rotated credentials on 2026-06-24. This is vendor research from a company selling the agent product, so only the disclosed chain and Snowflake's own confirming statement are carried here.
- Why it matters: An AI autofix removed an input-handling pattern that existed specifically to stop shell injection, and nothing in the review path caught that the replacement was exploitable by any user who could open an issue.
- Follow-up: Track whether GitHub documents a change to Copilot Autofix behaviour on shell-interpolation patterns.
send feedback on this story