In June 2026, a GitHub Actions script-injection flaw was introduced into Snowflake’s public snowflake-connector-net repository through a pull request that GitHub Copilot Autofix reviewed and approved as safe. Security firm Wiz’s autonomous “Red Agent” found the flaw during a routine scan on June 23, 2026, and used it to execute commands via a crafted GitHub issue title, gaining read access to Snowflake’s internal Jira covering engineering, security-compliance, and bug-bounty tracking projects. Snowflake patched the flaw the same day it was found. GitHub disputes that Copilot Autofix was responsible, saying its internal review found the vulnerable code was authored and approved by a human, not the AI tool.