PT-2026-53310 · Snowflake · Snowflake Cli
CVE-2026-13746
·
Published
2026-06-29
·
Updated
2026-06-30
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Snowflake CLI versions prior to 3.19
Description
Improper neutralization of local CLI parameters allows unintended SQL execution. A user can trigger this issue by providing crafted values to the Cortex SQL or object listing command paths, leading the Snowflake CLI to execute unauthorized SQL within the context of the user's session. Exploitation is limited to self-injection since parameters are supplied via local CLI arguments, and the impact is restricted to the privileges of the current session.
Recommendations
Update Snowflake CLI to version 3.19.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Snowflake Cli