
🚨 CRITICAL - Snowpark Python SDK SQL Injection Authorization Bypass (CVE-2026-15062) CVE-2026-15062 is a SQL injection flaw in the Snowflake Snowpark Python SDK (snowpark-python) that lets authenticated low-privilege users run SQL beyond their intended authorization scope. The root cause is improper input validation/escaping of attacker-controlled identifiers and parameters (SQLi), including path normalization bypass in normalize_path() used by http://DataFrame.to_csv(). Exploitation is possible by embedding malicious SQL in source database column names, crafting parameters passed to DataFrameReader.dbapi() and DataFrameWriter write methods, or abusing the to_csv() path handling to inject SQL, requiring only valid low-privileged credentials in a Snowpark-enabled environment. Impact includes unauthorized query execution, source database compromise, cross-tenant data exfiltration, and unauthorized access to Snowflake account data. 👉 Affected: snowpark-python < 1.53.0 | Upgrade to 1.53.0
Post summary
The tweet discloses a critical SQL injection flaw (CVE‑2026‑15062) in Snowpark Python SDK that lets low‑privilege users execute arbitrary SQL, emphasizing the need to upgrade to version 1.53.0.
