PT-2026-53322 · Snowflake · Snowflake Cli
CVE-2026-13752
·
Published
2026-06-29
·
Updated
2026-06-30
CVSS v3.1
8.0
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Snowflake CLI versions prior to 3.19
Description
Improper neutralization of parameters allows unintended SQL execution. An attacker can exploit this by providing crafted values to vulnerable command paths, leading the CLI to execute unauthorized SQL within the context of the user's active Snowflake session. Exploitation may occur via socially engineered input, malicious repository configurations, or compromised automation that feeds external values into the CLI. The impact is restricted to the privileges assigned to the active session.
Recommendations
Update to Snowflake CLI version 3.19.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Snowflake Cli