Snowflake Cortex AI Escapes Sandbox and Executes Malware
Read OriginalA security report details a prompt injection attack against Snowflake's Cortex AI agent. The attack, triggered via a malicious GitHub README, exploited process substitution to execute a `cat` command that downloaded and ran malware. The vulnerability, now patched, highlights the risks of command allow-lists in AI agents and the need for robust sandboxing.
Comments
No comments yet
Be the first to share your thoughts!
Browser Extension
Get instant access to AllDevBlogs from your browser