CVE-2025-24795Medium· 4.4▾ Sunlitsnowflake-connector-python vulnerable to insecure cache files permissions
▾ Sunlit zone — Low / medium · no exploitation signal
impact 24.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.1%
Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. On Linux systems, when temporary credential caching is enabled, the Snowflake Connector for Python will cache temporary credentials locally in a world-readable file.
This vulnerability affects versions 2.3.7 through 3.13.0. Snowflake fixed the issue in version 3.13.1.
On Linux, when either EXTERNALBROWSER or USERNAME_PASSWORD_MFA authentication methods are used with temporary credential caching enabled, the Snowflake Connector for Python will cache the temporary credentials in a local file. In the vulnerable versions of the Driver, this file is created with world-readable permissions.
Snowflake released version 3.13.1 of the Snowflake Connector for Python, which fixes this issue. We recommend users upgrade to version 3.13.1.
If you discover a security vulnerability in one of our products or websites, please report the issue to HackerOne. For more information, please see our Vulnerability Disclosure Policy.
snowflake-connector-python >= 2.3.7, < 3.13.1Upgrade to a patched release:
snowflake-connector-python 3.13.1Connected by shared product, vendor, weakness, or advisory.
CVE-2025-24794Medium· 6.7snowflake-connector-python vulnerable to insecure deserialization of the OCSP response cache
CVE-2025-24793High· 7.0snowflake-connector-python vulnerable to SQL Injection in write_pandas
CVE-2024-49750Medium· 5.5The Snowflake Connector for Python stores sensitive data in logs
CVE-2026-15925CriticalSnowflake Connector for Python improperly verifies TLS hostnames
CVE-2022-42965Medium· 5.9snowflake-connector-python is vulnerable to Regular Expression Denial of Service (ReDoS)
CVE-2026-85525High· 7.4Improper OCSP response validation in the Snowflake Python, Go, JDBC, and Node.js drivers allowed a revoked TLS certificate to be accepted as valid, because OCSP responses were not reliably bound to the certificate being validated and def…