CVE-2026-13744

Improper neutralization of attacker-controlled content in Snowflake CLI versions prior to 3.19 allowed unintended SQL execution. By supplying crafted repository content, project configuration, manifest data, or specification input, an attacker could cause Snowflake CLI to execute unintended SQL in the context of the victim user's Snowflake session. Successful exploitation requires the victim to process attacker-controlled content through a vulnerable command path and is limited by the privileges assigned to that session. The fix is available in Snowflake CLI version 3.19. Users must manually upgrade.
Configurations

Configuration 1 (hide)

cpe:2.3:a:snowflake:snowflake_cli:*:*:*:*:*:*:*:*

History

30 Jun 2026, 16:15

Type Values Removed Values Added
References () https://community.snowflake.com/s/article/Snowflake-CLI-Vulnerability-Advisory - () https://community.snowflake.com/s/article/Snowflake-CLI-Vulnerability-Advisory - Vendor Advisory
CPE cpe:2.3:a:snowflake:snowflake_cli:*:*:*:*:*:*:*:*
First Time Snowflake
Snowflake snowflake Cli

29 Jun 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-29 16:16

Updated : 2026-06-30 16:15


NVD link : CVE-2026-13744

Mitre link : CVE-2026-13744

CVE.ORG link : CVE-2026-13744


JSON object : View

Products Affected

snowflake

  • snowflake_cli
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')