PT-2026-53321 · Snowflake · Snowflake Cli
CVE-2026-13751
·
Published
2026-06-29
·
Updated
2026-06-30
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Snowflake CLI versions prior to 3.19
Description
Improper handling of untrusted remote references allows server-side request forgery (SSRF), a condition where a server is coerced into making requests to an unintended destination. The SQL statement reader's
!source and !load directives can reference remote URLs retrieved at runtime without sufficient restrictions on the destination. An attacker providing crafted SQL content processed through a vulnerable command path can force the victim's environment to send outbound requests to internal or non-public network locations. This can lead to remote SQL content being retrieved and executed within the context of the victim user's session, limited by the session's privileges.Recommendations
Update to version 3.19.
Disable remote URL retrieval using the option provided in version 3.19.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Snowflake Cli