An AI coding assistant reportedly introduced a vulnerability into Snowflake code, and another AI system later found and exploited it — inside a sanctioned vulnerability disclosure process, not a live breach. According to The Register, Wiz’s AI-powered offensive security agent found a GitHub Actions workflow flaw in Snowflake’s public snowflakedb/snowflake-connector-net repository during a routine scan on June 23. The report says the vulnerability let an unauthenticated user execute arbitrary commands inside a GitHub Actions runner by opening a GitHub issue with a specially crafted title. The notable part is the chain of automation on both sides. The Register reports that GitHub Copilot Autofix co-authored a June 18 commit that introduced the bug. The change allegedly removed an existing sanitized input pattern and replaced it with direct string expansion in a shell script inside run blocks, creating a script injection path. Wiz’s agent then used that path in a proof-of-concept exploit. Per The Register, the crafted issue title could break out of the expected string handling and trigger an out-of-band callback that exposed Jira credentials. Those credentials gave Wiz read access to Snowflake engineering, security compliance, and bug bounty tracking projects, according to the report. The incident was handled through Snowflake’s HackerOne vulnerability disclosure program. The Register says Wiz reported the workflow vulnerability on June 23, Snowflake patched it the same day, and the affected Jira token was revoked and rotated the following day. Snowflake told The Register it investigated and remediated the disclosure promptly, and that its review found no evidence of unauthorized access. The report also says Snowflake confirmed through audit logs that Wiz was the only third party to access the endpoint during the five-day exposure window. Wiz told The Register it deleted the data accessed during its vulnerability research and proof-of-concept testing. The security company also argued that the episode shows human review alone may not be enough to catch vulnerabilities quickly as AI-assisted development becomes more common. The Register notes Wiz has an interest in making that argument, but the underlying sequence it reports is still operationally relevant: AI-assisted code changes can affect CI/CD security, and autonomous agents can test those paths quickly. Who benefits: Wiz benefits from a visible proof point for its autonomous security agent, though The Register notes the company has a commercial interest in that framing. Snowflake benefits from having found and fixed the issue through a sanctioned bug bounty channel rather than after reported unauthorized exploitation. Who's exposed: Teams that use GitHub Actions workflows with user-controlled inputs are the clearest exposed group. The report also puts pressure on organizations adopting AI coding assistants to review generated changes to CI/CD scripts, not just application code.