๐Ÿ” CVE Alert

CVE-2026-13750

MEDIUM 5.5

Snowflake CLI Sensitive Credential Exposure Through Debug Logging

CVSS Score
5.5
EPSS Score
0.0%
EPSS Percentile
0th

Insertion of sensitive information into log files in Snowflake CLI versions prior to 3.19 allowed plaintext credentials to be written to persistent local debug logs. An attacker could exploit this by obtaining read access to the affected user's local log files, causing credentials such as passwords, tokens, or private key material to be exposed without additional application-level safeguards. Successful exploitation requires credentials to be present in the affected connection context and the resulting logs to be accessible from the local environment. The fix is available in Snowflake CLI version 3.19, and users must manually upgrade.

CWE CWE-532
Vendor snowflake
Product snowflake cli
Published Jun 29, 2026
Last Updated Jun 29, 2026
Stay Ahead of the Next One

Get instant alerts for snowflake snowflake cli

Be the first to know when new medium vulnerabilities affecting snowflake snowflake cli are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

Snowflake / Snowflake CLI
3.0.0 < 3.19.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
community.snowflake.com: https://community.snowflake.com/s/article/Snowflake-CLI-Vulnerability-Advisory