PT-2026-53322 · Snowflake · Snowflake Cli

CVE-2026-13752

·

Published

2026-06-29

·

Updated

2026-06-30

CVSS v3.1

8.0

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Snowflake CLI versions prior to 3.19
Description Improper neutralization of parameters allows unintended SQL execution. An attacker can exploit this by providing crafted values to vulnerable command paths, leading the CLI to execute unauthorized SQL within the context of the user's active Snowflake session. Exploitation may occur via socially engineered input, malicious repository configurations, or compromised automation that feeds external values into the CLI. The impact is restricted to the privileges assigned to the active session.
Recommendations Update to Snowflake CLI version 3.19.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-13752

Affected Products

Snowflake Cli