CVE 8.3 HIGH

Improper Command Detection Logic Allows RCE in Cortex Code Command-Line Interface_CVE-2026-6442

8.3 / 10
HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

Description

Improper validation of bash commands in Snowflake Cortex Code CLI versions prior to 1.0.25 allowed subsequent commands to execute outside the sandbox. An attacker could exploit this by embedding specially crafted commands in untrusted content, such as a malicious repository, causing the CLI agent to execute arbitrary code on the local device without user consent. Exploitation is non-deterministic and model-dependent. The fix is automatically applied upon relaunch with no user action required.

Basic Information

ID CVE-2026-6442
Source SNOWFLAKE
Published Apr 16, 2026 at 18:43
Modified Apr 16, 2026 at 18:54

Affected Product

Vendor Snowflake
Product Cortex Code CLI
Version <1.0.25
Affected Versions Snowflake Cortex Code CLI <1.0.25

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.