Snowflake Snowflake Cli — CVE-2026-13751 (Critical)

Date Jun 29, 2026
Type Vendor advisory
Signal Critical vendor advisory
Vendor / Product Snowflake · Snowflake Cli
CVE CVE-2026-13751
Critical vendor advisory CVE-2026-13751

Summary

Improper handling of untrusted remote references in Snowflake CLI versions prior to 3.19 allowed server-side request forgery. The SQL statement reader's !source/!load directives could reference remote URLs that were retrieved at runtime without sufficient restriction on the request destination. By supplying crafted SQL content processed through a vulnerable command path, an attacker could cause the victim's environment to issue unintended outbound requests to internal or otherwise non-public network locations, and could cause remote SQL content to be retrieved and executed in the context of th

Why it matters

This CVE carries a CRITICAL severity rating (CVSS 4.1) in Snowflake Snowflake Cli. Patch or mitigate promptly. EPSS percentile: 1%.

Operator check

Review CVE-2026-13751 in your asset inventory. Apply patches per vendor guidance and verify Snowflake Cli is not exposed. CVSS score: 4.1. EPSS probability: 0.1%; percentile: 1%.

Sources

PatchBrief uses public sources. It does not scan environments, verify exposure, or replace vendor guidance.