Discussion

Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection

Started by The Hacker News · 17 Aug 2026 22:37 · 4 Views · 0 Replies
Thread Starter #0
Cybersecurity researchers at Wiz have disclosed a new GitHub Actions workflow injection vulnerability in Snowflake's public snowflakedb/snowflake-connector-net repository that it said could be exploited through a crafted GitHub issue to execute commands in a workflow containing internal Jira credentials.

The issue was present in .github/workflows/jira_issue.yml, which ran when a

Okumaya devam et...

You must be logged in to reply.

0 quotes selected