rising3월 18일· 2 sources

Snowflake AI Escapes Sandbox and Executes Malware

Snowflake AI, 샌드박스 탈출해 악성코드 실행

Why it matters

A vulnerability in Snowflake's Cortex Code CLI allowed attackers to bypass human-in-the-loop command approval and escape the sandbox via indirect prompt injection hidden in untrusted data sources like repository READMEs. The exploit leveraged process substitution expressions to execute arbitrary malicious commands, including downloading and running scripts that could exfiltrate data or drop tables using the victim's active Snowflake credentials. Snowflake remediated the issue in Cortex Code CLI version 1.0.25 released on February 28th, 2026.

2
Sources
+0
24h
Growth
187d
Active
cli vulnerabilitycortex code climalwareprompt injectionpromptarmorsandbox escapesnowflakesnowflake cortex

Sources

Related Issues