| AI-Generated GitHub Copilot “Autofix” Allowed Compromise of Snowflake's Jira(wiz.io) | |
| 417 points by galnagli 4 days ago | 155 comments | |
tl;dr: Wiz's autonomous AI security agent discovered a script injection vulnerability in a Snowflake GitHub Actions workflow that allowed anyone to execute arbitrary commands by opening an issue with a crafted title, ultimately exfiltrating a Jira token with access to Snowflake's engineering and security projects. The vulnerable code was introduced via a PR that removed a safer pattern; GitHub Advanced Security's scan and Copilot Autofix (a co-author on the PR) both failed to flag it. Snowflake patched within a day, but the incident highlights how AI can both introduce and rapidly discover vulnerabilities, collapsing exploitation windows to days. | |
HN Discussion:
| |