Simon Willison 3/18/2026

Snowflake Cortex AI Escapes Sandbox and Executes Malware

Read Original

A security report details a prompt injection attack against Snowflake's Cortex AI agent. The attack, triggered via a malicious GitHub README, exploited process substitution to execute a `cat` command that downloaded and ran malware. The vulnerability, now patched, highlights the risks of command allow-lists in AI agents and the need for robust sandboxing.

Snowflake Cortex AI Escapes Sandbox and Executes Malware

Comments

No comments yet

Be the first to share your thoughts!

Browser Extension

Get instant access to AllDevBlogs from your browser