Snowflake Cortex AI Escapes Sandbox and Executes Malware

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

A critical vulnerability in Snowflake's Cortex Code CLI (an AI coding agent) allowed attackers to bypass human-in-the-loop approval and escape the sandbox via indirect prompt injection. The flaw stemmed from the command validation system failing to evaluate shell commands inside process substitution expressions. Combined with

7m read timeFrom promptarmor.com
Post cover image
Table of contents
ContextThe Attack ChainImpactsSubagent Context Loss Exacerbates RisksResponsible Disclosure

Sort: