—
PYSEC-2025-28
Quick fix
PYSEC-2025-28 — snowflake-connector-python: upgrade to the fixed version with the command below.
pip install --upgrade 'snowflake-connector-python>=3769b43822357c3874c40f5e74068458c2dc79af'Details
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. On Linux systems, when temporary credential caching is enabled, the Snowflake Connector for Python will cache temporary credentials locally in a world-readable file. This vulnerability affects versions 2.3.7 through 3.13.0. Snowflake fixed the issue in version 3.13.1.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/snowflake-connector-python
Introduced in:
0Fixed in: 3769b43822357c3874c40f5e74068458c2dc79afFix
pip install --upgrade 'snowflake-connector-python>=3769b43822357c3874c40f5e74068458c2dc79af'