PT-2026-53309 · Snowflake · Snowflake Cli
CVE-2026-13744
·
Published
2026-06-29
·
Updated
2026-07-01
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Snowflake CLI versions prior to 3.19
Description
Improper neutralization of attacker-controlled content allows unintended SQL execution. An attacker can execute arbitrary SQL within the context of a victim user's Snowflake session by providing crafted repository content, project configuration, manifest data, or specification input. Exploitation occurs when a victim processes this malicious content through a vulnerable command path, and the impact is limited by the privileges assigned to the active session.
Recommendations
Upgrade to version 3.19.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Snowflake Cli