Impact
The Snowflake CLI prior to version 3.27.0 fails to properly validate user‑supplied values, allowing these values to be interpolated into SQL strings that the CLI executes as multi‑statement queries. This is a classic SQL injection vulnerability (CWE‑89) that can give an attacker the ability to execute arbitrary SQL commands within the Snowflake session and the role that the CLI is running under. Depending on the privileges of that role, the attacker may read, modify, or delete data and alter Snowflake objects.
Affected Systems
All users of Snowflake’s command‑line interface who are running a version older than 3.27.0 are affected. The affected product is the Snowflake CLI, and the vendor is Snowflake. No narrower version range is specified beyond the pre‑3.27.0 statement.
Risk and Exploitability
The base CVSS score of 8.2 represents a high severity. No EPSS score is available, so the current exploitation likelihood is not quantified, but the absence of a low EPSS does not reduce the inherent risk. The vulnerability is not listed in the CISA KEV catalog, indicating no widespread exploitation has been reported. Attackers must obtain control over a project configuration file or inject malicious values via command‑line arguments in a CI/CD pipeline that runs Snowflake CLI with an elevated service‑account role. Successful exploitation therefore requires either write or pull‑request access to a project repository with such a pipeline, or the ability to supply untrusted input to automation that invokes the CLI. Thus the attack vector is oriented toward internal development or integration environments rather than direct external network exposure.
OpenCVE Enrichment