CVE-2026-6442Disclosure

LOWCVSS 8.3 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper validation of bash commands in Snowflake Cortex Code CLI versions prior to 1.0.25 allowed subsequent commands to execute outside the sandbox. An attacker could exploit this by embedding specially crafted commands in untrusted content, such as a malicious repository, causing the CLI agent to execute arbitrary code on the local device without user consent. Exploitation is non-deterministic and model-dependent. The fix is automatically applied upon relaunch with no user action required.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1286

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-17); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-17: 1Mentions · 2026-04-22: 1Technical Details · 2026-04-17: 104-1704-22
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-04-171
Disclosure1
2026-04-221
General1
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-6442 Improper validation of bash commands in Snowflake Cortex Code CLI versions prior to 1.0.25 allowed subsequent commands to execute outside the sandbox. An attacker could… https://www.cve.org/CVERecord?id=CVE-2026-6442

    Post summary

    The post announces CVE‑2026‑6442, outlining its nature and affected software, but provides no evidence of exploits, active attacks, patches, or falsification claims.

    0001182
    57.2K followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-6442: Snowflake Cortex Code CLI Command Injection - What It Means for Your Business and How to Respond https://hubs.li/Q04d1mRz0

    Post summary

    The brief title offers no concrete details about the CVE; it merely identifies the vulnerability and hints at a discussion of potential business impact.

    0000040
    29 followersView on X

Explore more