CVE-2026-13752: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Snowflake Snowflake CLI
Improper neutralization of parameters in Snowflake CLI versions prior to 3.19 allowed unintended SQL execution. An attacker could exploit this by supplying crafted values to vulnerable command paths, causing Snowflake CLI to execute unintended SQL in the context of the user’s Snowflake session. Successful exploitation required crafted values to reach vulnerable parameters, including through socially engineered input, malicious repository configuration, or compromised automation feeding external values into the CLI, and impact is limited by the privileges assigned to the active session. The fix is available in Snowflake CLI version 3.19, and users must manually upgrade.
AI Analysis
Technical Summary
This vulnerability involves improper neutralization of special elements in SQL commands within Snowflake CLI versions before 3.19. An attacker can supply crafted parameters to vulnerable command paths, leading to execution of unintended SQL statements in the context of the user's Snowflake session. Exploitation vectors include socially engineered input, malicious repository configurations, or compromised automation feeding external values into the CLI. The severity is medium with a CVSS 3.1 score of 6.0, reflecting local attack vector, high complexity, low privileges required, and user interaction needed. The impact includes potential unauthorized disclosure and modification of data limited by session privileges. Snowflake CLI version 3.19 contains the fix, requiring manual upgrade by users.
Potential Impact
Successful exploitation can lead to unauthorized SQL command execution within the user's Snowflake session, potentially resulting in high confidentiality and integrity impact limited by the privileges of the active session. There is no impact on availability. The attack requires local access with high complexity and user interaction.
Mitigation Recommendations
A patch is available in Snowflake CLI version 3.19. Users should manually upgrade to this version to remediate the vulnerability. Since this is a client-side tool, remediation depends on user action to update the CLI. No other mitigations are specified.
CVE-2026-13752: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Snowflake Snowflake CLI
Description
Improper neutralization of parameters in Snowflake CLI versions prior to 3.19 allowed unintended SQL execution. An attacker could exploit this by supplying crafted values to vulnerable command paths, causing Snowflake CLI to execute unintended SQL in the context of the user’s Snowflake session. Successful exploitation required crafted values to reach vulnerable parameters, including through socially engineered input, malicious repository configuration, or compromised automation feeding external values into the CLI, and impact is limited by the privileges assigned to the active session. The fix is available in Snowflake CLI version 3.19, and users must manually upgrade.
CVSS v3.1
Score 6.0medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability involves improper neutralization of special elements in SQL commands within Snowflake CLI versions before 3.19. An attacker can supply crafted parameters to vulnerable command paths, leading to execution of unintended SQL statements in the context of the user's Snowflake session. Exploitation vectors include socially engineered input, malicious repository configurations, or compromised automation feeding external values into the CLI. The severity is medium with a CVSS 3.1 score of 6.0, reflecting local attack vector, high complexity, low privileges required, and user interaction needed. The impact includes potential unauthorized disclosure and modification of data limited by session privileges. Snowflake CLI version 3.19 contains the fix, requiring manual upgrade by users.
Potential Impact
Successful exploitation can lead to unauthorized SQL command execution within the user's Snowflake session, potentially resulting in high confidentiality and integrity impact limited by the privileges of the active session. There is no impact on availability. The attack requires local access with high complexity and user interaction.
Mitigation Recommendations
A patch is available in Snowflake CLI version 3.19. Users should manually upgrade to this version to remediate the vulnerability. Since this is a client-side tool, remediation depends on user action to update the CLI. No other mitigations are specified.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- SNOWFLAKE
- Date Reserved
- 2026-06-29T16:23:15.621Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
- Is Cloud Service
- true
Threat ID: 6a42a9a827e9c79719324a26
Added to database: 06/29/2026, 17:21:44 UTC
Last enriched: 06/29/2026, 17:36:22 UTC
Last updated: 08/13/2026, 12:41:08 UTC
Views: 85
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.