AI-Generated GitHub Copilot 'Autofix' Allowed Compromise of Snowflake's Jira

AI-Generated GitHub Copilot "Autofix" Allowed Compromise of Snowflake's Jira

AI-Generated GitHub Copilot 'Autofix' Allowed Compromise of Snowflake's Jira

Wiz Research's autonomous AI agent, Red Agent, discovered a critical GitHub Actions workflow vulnerability in Snowflake's public repository snowflake-connector-net. The flaw, introduced by a Copilot Autofix commit, allowed unauthenticated command execution via a crafted issue title, leading to the exfiltration of Jira credentials. Snowflake patched the issue the same day and rotated the affected credential. The incident highlights the security risks of AI-generated code and the need for rigorous oversight.

In other words, an AI “autofix” commit created the very injection vector.

More from this day

2026-08-17