GitHub Copilot의 실수로 Snowflake Jira가 침해될 가능성이 발견됐다.
Wiz의 Red Agent라는 자율 보안 도구가 Snowflake 공개 저장소의 GitHub 이슈 제목만으로 임의 명령 실행 및 Jira 자격 증명 탈취가 가능한 취약점을 발견했다. 이 취약점은 2026년 6월 18일에 병합된 PR #1218에서 기인하며, GitHub Actions와 관련된 문제로 보인다. 이 사건은 GitHub Copilot의 성능 문제와 관련성을 시사한다.
A vulnerability allowing Snowflake Jira compromise was found due to a GitHub Copilot oversight.
Wiz's autonomous security tool Red Agent discovered a vulnerability in the Snowflake public repository that allows arbitrary commands to be executed and Jira credentials to be stolen, based solely on GitHub issue titles. This vulnerability stems from a merged pull request (#1218) on June 18, 2026, which is related to GitHub Actions. This incident highlights issues surrounding GitHub Copilot's performance.