A New Vulnerability Found in Copilot — AI Agents Abuse CI/CD Pipelines to Attack Snowflake
GitHub Copilot Autofix introduced a vulnerability to Snowflake’s repository and the autonomous AI agent Wiz Red Agent exploited it to hijack a Jira token. It was done fully automatically.
A team of security researchers at Wiz identified GitHub Copilot Autofix suggested pull request (PR) #1218 in the Snowflake’s repository. It replaced a safer implementation with a direct interpolation of a task name into a shell command. A simple single quote character in the issue’s title helped it escape the string and run any arbitrary code.
Wiz Red Agent, an autonomous AI agent, discovered the vulnerability, modified its payload when it didn’t succeed initially, and hijacked the Jira token of the [email protected] account, which had access to Snowflake’s engineering, security, and bug-bounty projects. GitHub Advanced Security missed the injection. The vulnerability was there from June 18–23, 2026.
Why This Matters
It’s the first publicly disclosed incident where an end-to-end attack flow, from an AI-based vulnerability to its AI-powered exploitation, happened fully automatically. After Snowflake fixed the vulnerability on the same day and rotated the token, an audit showed that only Wiz accessed the token.
Source: www.wiz.io
Free course
Stop reading about AI — start building with it
The free Claude Code course: your first site, tool or game — no coding. No upsells, no cross-sells — nothing to buy here.
Start free →▌ Related guides

Author
Evgenii Arsentev
PhD · Chief Executive Officer, digital health
Articles · Latest articles