CVE-2026-15062 | Snowflake Snowpark Python SDK up to 1.52.x DataFrameWriter write methods location sql injection

SecurityVulns

A vulnerability was found in Snowflake Snowpark Python SDK up to 1.52.x. It has been declared as critical. Affected by this issue is the function DataFrameReader.dbapi/normalize_path/DataFrame.to_csv of the component DataFrameWriter write methods. The manipulation of the argument location results in sql injection.

This vulnerability is reported as CVE-2026-15062. The attack can be launched remotely. No exploit exists.VulDB Recent EntriesRead More