AI-Generated GitHub Copilot “Autofix” Allowed Compromise of Snowflake's Jira
Wiz Research's autonomous AI agent, Red Agent, discovered a critical script injection vulnerability in Snowflake's GitHub Actions workflow that allowed arbitrary command execution via a crafted issue title. The vulnerable code was introduced by a PR that included an AI-generated Copilot Autofix, which GitHub Advanced Security scanned but failed to flag the injection. The flaw, live for five days before discovery, enabled exfiltration of Jira credentials and access to Snowflake's internal systems.