Skip to content

[GHSA-872q-cxrp-279p] SQL injection vulnerabilities in the Snowflake Snowpark... - #9346

Open
zain-ul-abideen-5036 wants to merge 1 commit into
zain-ul-abideen-5036/advisory-improvement-9346from
zain-ul-abideen-5036-GHSA-872q-cxrp-279p
Open

[GHSA-872q-cxrp-279p] SQL injection vulnerabilities in the Snowflake Snowpark...#9346
zain-ul-abideen-5036 wants to merge 1 commit into
zain-ul-abideen-5036/advisory-improvement-9346from
zain-ul-abideen-5036-GHSA-872q-cxrp-279p

Conversation

@zain-ul-abideen-5036

Copy link
Copy Markdown

Updates

  • Affected products
  • References
  • Source code location
  • Summary

Comments
The advisory currently does not specify the affected package or complete version range.

The affected package is snowflake-snowpark-python in the pip ecosystem. The CVE record identifies Snowflake Snowpark Python SDK version 0.1.0 and later versions before 1.53.0 as affected, with version 1.53.0 providing the relevant fixes.

I suggest adding the following package metadata:

Ecosystem: pip
Package: snowflake-snowpark-python
Affected versions: >= 0.1.0, < 1.53.0
Patched version: 1.53.0

Supporting references:
https://nvd.nist.gov/vuln/detail/CVE-2026-15062
https://github.com/snowflakedb/snowpark-python/releases/tag/v1.53.0
https://pypi.org/project/snowflake-snowpark-python/1.53.0/

Adding this metadata would allow the advisory to identify affected dependencies and enable dependency-management tooling to recognize vulnerable and fixed versions.

Copilot AI balanced review requested due to automatic review settings September 4, 2026 16:57

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@github-actions
github-actions Bot changed the base branch from main to zain-ul-abideen-5036/advisory-improvement-9346 September 4, 2026 16:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants