PT-2026-33357 · Snowflake · Cortex Code Cli

Promptarmor

·

Published

2026-04-16

·

Updated

2026-04-22

·

CVE-2026-6442

CVSS v3.1

8.3

High

VectorAV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Snowflake Cortex Code CLI versions prior to 1.0.25
Description Improper validation of bash commands allows subsequent commands to execute outside the sandbox. An attacker can embed specially crafted commands in untrusted content, such as a malicious repository, leading to arbitrary code execution on the local device without user consent. This process is non-deterministic and depends on the model used.
Recommendations Update to version 1.0.25 or later. The fix is automatically applied upon relaunching the application.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-6442

Affected Products

Cortex Code Cli