PT-2026-53321 · Snowflake · Snowflake Cli

CVE-2026-13751

·

Published

2026-06-29

·

Updated

2026-06-30

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Snowflake CLI versions prior to 3.19
Description Improper handling of untrusted remote references allows server-side request forgery (SSRF), a condition where a server is coerced into making requests to an unintended destination. The SQL statement reader's !source and !load directives can reference remote URLs retrieved at runtime without sufficient restrictions on the destination. An attacker providing crafted SQL content processed through a vulnerable command path can force the victim's environment to send outbound requests to internal or non-public network locations. This can lead to remote SQL content being retrieved and executed within the context of the victim user's session, limited by the session's privileges.
Recommendations Update to version 3.19. Disable remote URL retrieval using the option provided in version 3.19.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-13751

Affected Products

Snowflake Cli