GitHub Copilot Autofix introduced a CI/CD injection bug that let Wiz's AI red agent access Snowflake's internal Jira
AI-Generated GitHub Copilot "Autofix" Allowed Compromise of Snowflake's Jira
Wiz's autonomous AI red agent found a script injection bug in a Snowflake public repo's GitHub Actions workflow and used it to exfiltrate internal Jira credentials. The vulnerability was introduced five days earlier by a Copilot Autofix commit that replaced a safe env-variable pattern with direct string interpolation into a shell script. A single quote in an issue title broke out of the echo command and allowed arbitrary code execution. The agent autonomously scanned, adapted its payload after a bash syntax error, and exfiltrated data with no human intervention. Snowflake fixed the issue and rotated credentials the same day; audit logs confirmed Wiz was the only actor.
Why it matters: AI writes buggy code, AI finds and exploits it—the loop is too clean to ignore. HKR all hit. Slight discount because it's a single incident rather than a systemic disclosure, and Wiz's product angle is prominent, but the story itself is solid at 82.