Snowflake Cli
Vendor:
First CVE: Jun 29, 2026 · Active for under a year
7
Total CVEs
More Total CVEs than 83% of tracked products
7.0
Avg CVEs / Year
Higher CVE frequency than 92% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 50% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Snowflake Cli over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 29, 2026
23 days ago
Most Recent CVE
Jun 29, 2026
24 days ago
CVE Severity & Scoring
Snowflake Cli7 CVEs
43%
43%
14%
All CVEs352,101 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (28.6%)
Network5 (71.4%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None2 (28.6%)
Unknown0 (0.0%)
Required5 (71.4%)
Privileges Required
Low3 (42.9%)
High0 (0.0%)
None4 (57.1%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-13749HIGH Improper neutralization in the Snowpark annotation processor callback template in Snowflake CLI versions prior to 3.19 allowed arbitrary code execution during application bundling | Jun 29, 2026 | 8.8 | 39 | NO | NO |
CVE-2026-13751CRITICAL Improper handling of untrusted remote references in Snowflake CLI versions prior to 3.19 allowed server-side request forgery. The SQL statement reader's !source/!load directives co | Jun 29, 2026 | 9.6 | 38 | NO | NO |
CVE-2026-13744HIGH Improper neutralization of attacker-controlled content in Snowflake CLI versions prior to 3.19 allowed unintended SQL execution. By supplying crafted repository content, project co | Jun 29, 2026 | 8.8 | 38 | NO | NO |
CVE-2026-13752HIGH Improper neutralization of parameters in Snowflake CLI versions prior to 3.19 allowed unintended SQL execution. An attacker could exploit this by supplying crafted values to vulner | Jun 29, 2026 | 8.0 | 35 | NO | NO |
CVE-2026-13748MEDIUM Improper restriction of file path resolution in Snowflake CLI versions prior to 3.19 allowed arbitrary local file content to be read and transmitted to Snowflake services. An attac | Jun 29, 2026 | 6.3 | 31 | NO | NO |
CVE-2026-13750MEDIUM Insertion of sensitive information into log files in Snowflake CLI versions prior to 3.19 allowed plaintext credentials to be written to persistent local debug logs. An attacker co | Jun 29, 2026 | 5.5 | 28 | NO | NO |
CVE-2026-13746MEDIUM Improper neutralization of local CLI parameters in Snowflake CLI versions prior to 3.19 allowed unintended SQL execution. A user could trigger this issue by supplying crafted value | Jun 29, 2026 | 5.4 | 26 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (7 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (7 CVEs).
Media Mentions
Signals from CVEs in this product scope (7 CVEs).
Top CWEs
Versions
No cataloged versions.