Product1 distinct publisher3 min readUpdated
Wiz withdrew the load-bearing part of its Snowflake finding after GitHub's review. The defect underneath is ordinary workflow syntax: untrusted input substituted before sanitisation, behind a guard that never fires.
The Product Desk · Product desk

Compiled by The Product DeskSomething wrong?How this is made
A security company said on Monday that an AI wrote a critical flaw into Snowflake's code and that another AI found it and broke in; the first half came apart in about eight hours [0]. What is left is a piece of ordinary GitHub Actions syntax, and that is the part that transfers to other people's repositories rather than to a press cycle. Wiz Research runs an autonomous scanner it calls Red Agent [1]. Under Snowflake's HackerOne programme it flagged a workflow file in the public repository for the company's .NET connector [2]. The workflow ran whenever anyone opened an issue, dropped the issue title straight into a shell script, and was reachable by any account on the internet [3]. The escaping existed but sat in the wrong order: GitHub's template engine substituted the title first and the sanitising commands ran afterwards, so a single quote in a title broke out of the shell string [4]. The second defect is the more instructive one. A guard condition compared a pull request property against a bot name; on issue events that property does not exist, GitHub evaluates a missing property as an empty string, and the comparison therefore returned true for everyone [5]. That line reads as a bot check and functions as an open door, and it will read the same way in any workflow that reuses a pull-request condition under an issue trigger. The exploitation is not disputed. Red Agent's first payload used a hash to comment out the rest of the line, the runner threw a syntax error, the agent read the error, worked out that the comment had swallowed a closing bracket, rewrote the payload and got its callback within seconds, with nobody at a keyboard [6]. The token it retrieved granted read access across Snowflake's engineering, security compliance and bug bounty projects [7]. Wiz reported on 23 June, Snowflake patched the same day, restored the safe pattern and rotated the Jira token on 24 June [8]. Audit logs matched every anomalous query to Wiz's own testing addresses, and Wiz says it deleted what it took [9]. Snowflake says the disclosure "was received on June 23, 2026, and it was immediately investigated and remediated," and that its investigation found no evidence of unauthorised access [10]. The headline died on provenance. The commit that carried the flaw onto main lists "Copilot Autofix powered by AI" among its co-authors, which Wiz read as an AI writing the vulnerable code [11]. Copilot's co-authored commit changed a different file; the unsafe refactor is a separate commit dated 25 August 2025 that GitHub attributes to a named Snowflake engineer [12]. Squashing folds a pull request into one commit and carries the co-author line with it, recording participation rather than authorship [13]. GitHub's internal review says a human wrote the contributions that led to the vulnerability and that Copilot Autofix neither reviewed nor contributed to them [15]. Wiz's own update, timestamped 19:57 UTC, now says "It's unclear whether the code-change was AI-assisted" [16]. The Register reversed its headline, appended a correction, and said it "won't be trusting Wiz for a very long time" [17]. Google owns Wiz; Microsoft owns GitHub, and Copilot with it [18]. One number does not sit right either. The account says the flaw was live for five days [19], while the refactor that introduced it is dated 25 August 2025 and the disclosure landed on 23 June 2026, roughly ten months apart [20]. Two things to watch. Neither Wiz nor GitHub, in this account, put a figure on how many other public workflows substitute untrusted issue text before sanitisation or gate an issue trigger on a pull-request property [21]; that count is the real scope of the finding, and it is unpublished.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
A security company said on Monday that an AI wrote a critical flaw into Snowflake's code and that another AI found it and broke in; the second half holds up, and the first half came apart in about eight hours.
The escaping sat in the wrong order: GitHub's template engine substituted the issue title first and the commands meant to sanitise it ran afterwards, so a single quote in the title broke out of the shell string.
The token the agent extracted granted read access across Snowflake's engineering, security compliance, and bug bounty projects.
Audit logs matched every anomalous query to Wiz's own testing addresses, and Wiz says it deleted what it took.
Snowflake said: "The disclosure was received on June 23, 2026, and it was immediately investigated and remediated, and our investigation found no evidence of unauthorized access."
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Verifiable commit trail, unverifiable blast radius, one outlet
The technical core is checkable in public artefacts: the workflow defects are described at code level, and the authorship dispute is resolved against commit dates and file scope plus GitHub's on-record review statement. Against that, the cluster is a single publisher, there is no CVE, CVSS score or exploited-vulnerability catalogue entry, and every blast-radius fact rests on unpublished Snowflake and Wiz artefacts. The central factual conflict over whether Copilot Autofix reviewed the pull request remains unresolved by design.
One repository, patched the same day, no downstream release
Observed real-world footprint is narrow: a single public repository's automation, exploited once by the disclosing researcher, patched the day it was reported with the token rotated the next day. The weakness sat in repository automation, so no connector release carried it, and no evidence points to any other party exploiting it. The extracted token's cross-project read scope is what keeps this above negligible.
Headline claim withdrawn; defect underneath is ordinary
The load-bearing assertion — that an AI wrote the vulnerable code — was withdrawn within hours after GitHub's review, and the originating vendor's own update conceded it is unclear whether the change was AI-assisted. A downstream outlet corrected its headline and publicly withdrew trust in the source. The surviving finding is a well-known Actions injection pattern that GitHub had already warned about, plus a competent agentic exploit chain. The account's own five-day exposure claim also sits unreconciled against a commit dated roughly ten months before disclosure, adding to the overstatement.
Rival-owned vendors, one holding the deciding logs
The disclosing firm is Google-owned and the accused product is Microsoft-owned, and the disputed claim ran in the direction of the accuser's commercial interest while also advertising its own autonomous red-team capability. GitHub's rebuttal serves its product's reputation equally. Neither side's incentive is neutral, and only one party holds the logs that would settle whether AI review passed the change, which the account states plainly.
Single outlet, two open contradictions
Confidence is moderate-to-low: one publisher, no independent corroboration inside the cluster, and two unresolved contradictions — the Wiz-versus-GitHub account of whether Copilot Autofix reviewed the pull request, and the five-day exposure window against a ten-month commit interval. The remediation timeline and the workflow mechanics are the most reliable parts of the record; severity and blast radius are the least.
build
Grok 4.6 lands in Copilot two days after launch, and the model picker becomes a procurement problem1 distinct publisher
security
The AI security line item to fund first is log coverage, not another agent2 distinct publishers
build
Agent Plugins 1.0.0 standardises file paths. Anthropic still owns the behaviour.1 distinct publisher
product
Washington's secret AI test is coming for open weights, and release dates go with it2 distinct publishers
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 17, 2026