All Topics
All Topics
Technology
Technology
Design
Design
Programming
Programming
Science
Science
News
News
Gaming
Gaming
Entertainment
Entertainment
Business
Business
Finance
Finance
Sports
Sports
Health
Health
Food
Food
Travel
Travel
Art
Art
Music
Music
Books
Books
Education
Education
Politics
Politics
Personal
Personal
No algorithm. No AI slop. No ads. Just RSS. Pro-human. Indie writers. Real journalism. Open web. Chronological. Hand toasted.

Security Vulnerability in Snowflake Cortex Code CLI Allows Malware Execution via Prompt Injection

By

ozgune

2mo ago· 7 min readenNews

Summary

A security vulnerability was discovered in Snowflake's Cortex Code CLI tool just two days after its release. The vulnerability allowed attackers to bypass the tool's command validation system through indirect prompt injection, enabling malicious commands to download and execute scripts without human approval. This could lead to data exfiltration and other malicious actions using the victim's active credentials within Snowflake's environment.

Key quotes

· 3 pulled
Two days after release, a vulnerability was identified in Cortex Code's command validation system that allowed specially constructed malicious commands
via indirect prompt injection, an attacker could manipulate Cortex to download and execute scripts without approval that leverage the victim's active credentials to perform malicious actions in Snowflake
A vulnerability in the Snowflake Cortex Code CLI allowed malware to be installed and executed via indirect prompt injection, bypassing human-in-the-loop command approval and escaping the sandbox
Snippet from the RSS feed
A vulnerability in the Snowflake Cortex Code CLI allowed malware to be installed and executed via indirect prompt injection, bypassing human-in-the-loop command approval and escaping the sandbox.

You might also wanna read