Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.6

CVE-2026-13751: Snowflake CLI versions before 3.19 allow malicious requests to internal networks

CVE-2026-13751
Summary

If you're using an older version of Snowflake CLI, a malicious SQL statement could trick your system into sending unauthorized requests to internal networks. To protect yourself, update to Snowflake CLI version 3.19 or later, which includes a feature to disable this behavior. If an update isn't possible, consider disabling remote URL retrieval as a temporary solution.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
snowflake snowflake_cli >= 1.1.0, < 3.19.0
cpe:2.3:a:snowflake:snowflake_cli:*:*:*:*:*:*:*:*
Original title
Improper handling of untrusted remote references in Snowflake CLI versions prior to 3.19 allowed server-side request forgery. The SQL statement reader's !source/!load directives could reference rem...
Original description
Improper handling of untrusted remote references in Snowflake CLI versions prior to 3.19 allowed server-side request forgery. The SQL statement reader's !source/!load directives could reference remote URLs that were retrieved at runtime without sufficient restriction on the request destination. By supplying crafted SQL content processed through a vulnerable command path, an attacker could cause the victim's environment to issue unintended outbound requests to internal or otherwise non-public network locations, and could cause remote SQL content to be retrieved and executed in the context of the victim user's session. Successful exploitation requires the victim to process attacker-controlled content through a vulnerable command path and is limited by the privileges available to that session and environment. The fix is available in Snowflake CLI version 3.19, which adds an option to disable remote URL retrieval.
nvd CVSS3.1 4.1
Vulnerability type
CWE-829
CWE-918 Server-Side Request Forgery (SSRF)
Published: 29 Jun 2026 · Updated: 2 Jul 2026 · First seen: 29 Jun 2026