
Sandbox escape in Cortex Code CLI enables local code execution
CVE-2026-6442 reports a High-severity sandbox escape in Snowflake's Cortex Code CLI (<1.0.25) where crafted `bash` commands from untrusted content can execute code locally without user consent.



















