Wiz reports that GitHub Copilot Autofix introduced a GitHub Actions workflow-injection flaw in a public Snowflake repository, letting its Red Agent exploit the AI-generated change and validate access to sensitive internal Jira data.
AI-Generated GitHub Copilot "Autofix" Allowed Compromise of Snowflake's Jira
Wiz reports that GitHub Copilot Autofix introduced a GitHub Actions workflow-injection flaw in a public Snowflake repository, letting its Red Agent exploit the AI-generated change and validate access to sensitive internal Jira data.
Source: Wiz