AI-Generated Copilot Code Led to Snowflake Jira Compromise

TL;DR. An AI-generated fix by GitHub Copilot introduced a critical vulnerability in a Snowflake repository, allowing unauthenticated access to Jira. - Wiz Research's AI-powered "Red Agent" autonomously discovered the vulnerability five days after its introduction. - The flaw enabled script injection via crafted GitHub issue titles, granting access to Snowflake's Jira portal. - Snowflake remediated the issue quickly and confirmed no data exfiltration beyond Wiz's proof-of-concept.

Sources

Back to QLANKR News