GitHub Workflow Flaw in Snowflake Repo Shows Risk of Automated Issue Handling
Security researchers at Wiz have disclosed a workflow injection vulnerability in a public GitHub repository maintained by Snowflake, the cloud data company. The flaw was found in an automated workflow file used to sync GitHub issues with Jira, which ran automatically whenever a new issue was created or edited.
Because the workflow processed user-supplied text from GitHub issues without properly sanitising it, an attacker could craft a malicious issue title or body designed to execute unintended commands within the workflow. This type of attack, known as workflow injection, could potentially expose sensitive internal credentials, including those used to connect to Jira, if the workflow's permissions were broad enough.
This case highlights a growing risk area: automation tools like GitHub Actions are convenient but can become attack surfaces if they process untrusted input, such as public issue submissions, without careful validation. Even businesses that don't manage large open-source projects should be aware that similar automation risks exist wherever external input triggers internal processes or credentials.