AI-Generated GitHub Copilot "Autofix" Allowed Compromise of Snowflake's Jira
Summary
Wiz Red Agent independently discovered and exploited a GitHub Actions vulnerability in Snowflake’s public repository, introduced via an AI-assisted Copilot Autofix commit. The exploit allowed script-injection through untrusted input in a workflow, leading to exposure of Jira credentials during a limited window before Snowflake remediated and rotated credentials. The incident highlights the security risks of AI-generated code changes in CI/CD pipelines and the need for rapid patching, robust guardrails, and thorough forensics.