// GitHubCRITICAL
A GitHub Actions injection vulnerability in Snowflake's public snowflake-connector-net repository allowed unauthenticated attackers to execute arbitrary commands on GitHub-hosted runners and steal internal credentials. The flaw exploited unsafe expression interpolation in a workflow triggered by issue creation, bypassing security gates. Active for five days (June 18–23, 2026), it was discovered by Wiz Red Agent and remediated immediately upon disclosure.
// Get alerts for GitHub