CVE-2026-13751
Snowflake Snowflake CLI, snowflake cli
Improper handling of untrusted remote references in Snowflake CLI versions prior to 3.19 allowed server-side request forgery. The SQL statement reader's !source/!load directives could reference remote URLs that were retrieved at runtime without sufficient restriction on the request destination. By supplying crafted SQL content processed through a vulnerable command path, an attacker could cause the victim's environment to issue unintended outbound requests to internal or otherwise non-public network locations, and could cause remote SQL content to be retrieved and executed in the context of...
- CVSS
- 9.6
- EPSS
- 0.12% 1.98% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.30