SECURITY·중요도 8·2026. 08. 17.·GeekNews

GitHub Copilot이 놓친 수정으로 Snowflake Jira 침해 가능해져

── KO ──────────────────

GitHub Copilot의 실수로 Snowflake Jira가 침해될 가능성이 발견됐다.

Wiz의 Red Agent라는 자율 보안 도구가 Snowflake 공개 저장소의 GitHub 이슈 제목만으로 임의 명령 실행 및 Jira 자격 증명 탈취가 가능한 취약점을 발견했다. 이 취약점은 2026년 6월 18일에 병합된 PR #1218에서 기인하며, GitHub Actions와 관련된 문제로 보인다. 이 사건은 GitHub Copilot의 성능 문제와 관련성을 시사한다.


── EN ──────────────────

A vulnerability allowing Snowflake Jira compromise was found due to a GitHub Copilot oversight.

Wiz's autonomous security tool Red Agent discovered a vulnerability in the Snowflake public repository that allows arbitrary commands to be executed and Jira credentials to be stolen, based solely on GitHub issue titles. This vulnerability stems from a merged pull request (#1218) on June 18, 2026, which is related to GitHub Actions. This incident highlights issues surrounding GitHub Copilot's performance.

원문 보기 →목록으로