GHSA-gxp8-hq7m-332h · Severity: high — Improper neutralization in the Snowpark annotation processor callback template in Snowflake CLI...
Improper neutralization in the Snowpark annotation processor callback template in Snowflake CLI versions prior to 3.19 allowed arbitrary code execution during application bundling or deployment. An attacker could exploit this by supplying crafted project content that is interpolated into generated Python code, causing Snowflake CLI to execute attacker-controlled code in the local context of the user running the CLI. Successful exploitation requires the victim to run the relevant bundling or deployment workflow against attacker-controlled project content, and any resulting code runs with the privileges of that local execution context. The fix is available in Snowflake CLI version 3.19, and users must manually upgrade.
Conclusion & alert: CVE-2026-13749 is rated Moderate Risk (45.3/100): CVSS High severity, with low exploitation likelihood (EPSS 0.37%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-30 | — | 0.37% | — |
Full EPSS history (1 record total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.8 | 3.1 | HIGH |
|
2.8 | 5.9 | 412d305a-227d-44f9-a262-a31ba44f2aea |
GHSA-gxp8-hq7m-332h · Severity: high — Improper neutralization in the Snowpark annotation processor callback template in Snowflake CLI...
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| snowflake | snowflake_cli | >= 2.4.0, < 3.19.0 | cpe:2.3:a:snowflake:snowflake_cli:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://community.snowflake.com/s/article/Snowflake-CLI-Vulnerability-Advisory | Vendor Advisory |