An autonomous AI agent found a critical vulnerability that GitHub Copilot missed

Started by Kevin71, Yesterday at 08:43 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Topic: An autonomous AI agent found a critical vulnerability that GitHub Copilot missed   Views(Read 35 times)
Active members in this topic:
Kevin71(1)

Kevin71

Security firm Wiz published research this week describing how its autonomous Red Agent independently discovered and exploited a GitHub Actions workflow vulnerability in one of Snowflake's public repositories, all without a human in the loop guiding the process. The flaw sat in a workflow file called jira_issue.yml inside the snowflake-connector-net repository, and it allowed an attacker to execute arbitrary commands within a GitHub Actions runner just by opening a crafted GitHub issue with a specially built title.

The timeline is what makes this story land harder than a typical vulnerability disclosure. The vulnerable code went live on June 18 when a pull request merged into the default branch, and Wiz's Red Agent independently found and exploited it just five days later while conducting routine security research through Snowflake's public HackerOne bug bounty program. The agent extracted a Jira token, validated access to sensitive data inside Snowflake's internal Jira environment, and assessed the blast radius, all according to Wiz without a human directing each step along the way.

Wiz initially framed the story around GitHub Copilot Autofix, an AI tool meant to catch and fix security bugs, claiming it had actually co authored the vulnerable code change that introduced the flaw in the first place. That framing spread fast across tech coverage because the irony was obvious and juicy, an AI security tool introducing a bug that another AI security tool later found and exploited. GitHub pushed back hard on that specific claim, saying its internal review found the vulnerable contribution was authored by a human and that Copilot Autofix neither reviewed nor contributed to the change.

Wiz softened its own framing later the same evening, updating the post to say Copilot was a co author that reviewed the merged pull request and marked it clear without catching the vulnerability, rather than having written the flawed code itself. The company's later statement includes the line that it is unclear whether the code change was AI assisted at all, which quietly undercuts a chunk of the original headline that most outlets had already run with by that point. The Register reportedly went as far as issuing a correction after initially running with the stronger claim.

Setting the authorship dispute aside, the underlying finding still matters on its own terms. Wiz's conclusion is that AI generated code, including pull requests from tools like Copilot Autofix, needs the same static analysis and security scrutiny as anything written by a person, and that guardrails need to exist to stop coding agents from swapping safe patterns for risky ones without historical context on why those safe patterns existed in the first place. Snowflake rotated the exposed Jira token and says its review found no evidence the token was accessed by anyone else during the five day exposure window

Question everything. Especially this.

Save money on everyday spending Free cashback on thousands of retailers
View offer