GitHub Copilot이 놓친 수정으로 Snowflake Jira 침해 가능해져
GitHub Copilot의 실수로 Snowflake Jira가 침해될 가능성이 발견됐다.
Wiz의 Red Agent라는 자율 보안 도구가 Snowflake 공개 저장소의 GitHub 이슈 제목만으로 임의 명령 실행 및 Jira 자격 증명 탈취가 가능한 취약점을 발견했다. 이 취약점은 2026년 6월 18일에 병합된 PR #1218에서 기인하며, GitHub Actions와 관련된 문제로 보인다. 이 사건은 GitHub Copilot의 성능 문제와 관련성을 시사한다.
A vulnerability allowing Snowflake Jira compromise was found due to a GitHub Copilot oversight.
Wiz's autonomous security tool Red Agent discovered a vulnerability in the Snowflake public repository that allows arbitrary commands to be executed and Jira credentials to be stolen, based solely on GitHub issue titles. This vulnerability stems from a merged pull request (#1218) on June 18, 2026, which is related to GitHub Actions. This incident highlights issues surrounding GitHub Copilot's performance.