Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Snowflake GitHub Actions Vulnerability Exposes Jira Credentials

Snowflake GitHub Actions Vulnerability Exposes Jira Credentials

Posted on August 17, 2026 By CWS

Introduction

A recent investigation by cybersecurity experts at Wiz has uncovered a significant vulnerability within Snowflake’s GitHub Actions workflow. This flaw, identified in the snowflakedb/snowflake-connector-net repository, could allow crafted GitHub issues to execute commands that expose internal Jira credentials.

The vulnerability resided in the .github/workflows/jira_issue.yml file, which operated upon the creation of a public issue. This flaw revealed critical information like JIRA_BASE_URL, JIRA_USER_EMAIL, and JIRA_API_TOKEN within the same workflow step. Although the flaw was found in the repository’s CI/CD automation, no official Snowflake Connector for .NET releases were compromised.

Details of the Vulnerability

The issue arose because the workflow directly inserted attacker-controlled data into a shell run: block. It erroneously checked a non-existent pull request property, allowing ordinary issues to reach the job despite comparisons against certain bot users.

Wiz’s Red Agent system was able to exploit this vulnerability during an authorized security test, receiving an out-of-band callback from the GitHub Actions runner. This enabled them to extract the Jira API token, which was linked to [email protected], granting read access to various Jira projects.

Response and Resolution

Wiz notified Snowflake of the issue through HackerOne on June 23, 2026. A swift response followed with the merging of a fix on the same day, which involved replacing direct GitHub expression expansions with environment variables as arguments to jq.

The problematic workflow had been part of the main branch since June 18, following a merged pull request. Snowflake’s statement, shared by Wiz, assured that no unauthorized access had been detected. The Jira token was rotated promptly on June 24, and no external misuse was observed during the exposure period.

Implications and Future Outlook

This security lapse was attributed to a GitHub Copilot Autofix change, although the specific vulnerable code was not directly authored by Copilot. The refactor traced back to a separate commit from August 2025, but was later integrated into a squash merge commit with Copilot involved as a co-author.

GitHub had previously highlighted this type of workflow injection risk, advising against the inclusion of untrusted data in run: blocks. As of August 17, 2026, there had been no CVE or CVSS score assigned, nor any updates to connector releases due to the vulnerability.

Conclusion

This incident underlines the importance of rigorous security measures in software development workflows. While no evidence of malicious exploitation was found, the fast response by Snowflake serves as a reminder of the need for vigilance and quick action in the face of potential cyber threats.

The Hacker News Tags:Automation, CI/CD, Credentials, cyber threats, Cybersecurity, data breach, DevOps, GitHub, GitHub actions, Jira, Security, security flaw, Snowflake, software development, Vulnerability

Post navigation

Previous Post: OpenMatter Highlights Verification at Belgrade Blockchain
Next Post: Critical GitLab Flaw Allows Project Deletion Risk

Related Posts

GitHub Actions Abused in New Cyberattack on cPanel Servers GitHub Actions Abused in New Cyberattack on cPanel Servers The Hacker News
Salt Typhoon Exploits Cisco, Ivanti, Palo Alto Flaws to Breach 600 Organizations Worldwide Salt Typhoon Exploits Cisco, Ivanti, Palo Alto Flaws to Breach 600 Organizations Worldwide The Hacker News
Researchers Expose TA585’s MonsterV2 Malware Capabilities and Attack Chain Researchers Expose TA585’s MonsterV2 Malware Capabilities and Attack Chain The Hacker News
Vibe-Coded Malicious VS Code Extension Found with Built-In Ransomware Capabilities Vibe-Coded Malicious VS Code Extension Found with Built-In Ransomware Capabilities The Hacker News
Continuous Threat Exposure Management: A Critical Security Solution Continuous Threat Exposure Management: A Critical Security Solution The Hacker News
Axios Abuse and Salty 2FA Kits Fuel Advanced Microsoft 365 Phishing Attacks Axios Abuse and Salty 2FA Kits Fuel Advanced Microsoft 365 Phishing Attacks The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical GitLab Flaw Allows Project Deletion Risk
  • Snowflake GitHub Actions Vulnerability Exposes Jira Credentials
  • OpenMatter Highlights Verification at Belgrade Blockchain
  • Achieving IAM Compliance: Essential Guidelines
  • Hackers Exploit Expired Domains for Scams and Malware

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical GitLab Flaw Allows Project Deletion Risk
  • Snowflake GitHub Actions Vulnerability Exposes Jira Credentials
  • OpenMatter Highlights Verification at Belgrade Blockchain
  • Achieving IAM Compliance: Essential Guidelines
  • Hackers Exploit Expired Domains for Scams and Malware

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark