Snowflake Cortex AI Escapes Sandbox and Executes Malware
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
A critical vulnerability in Snowflake's Cortex Code CLI (an AI coding agent) allowed attackers to bypass human-in-the-loop approval and escape the sandbox via indirect prompt injection. The flaw stemmed from the command validation system failing to evaluate shell commands inside process substitution expressions. Combined with
Table of contents
ContextThe Attack ChainImpactsSubagent Context Loss Exacerbates RisksResponsible DisclosureSort: