CVE Tools

GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding Agents

The Hacker NewsBy The Hacker News

ResearchAmazon Q DeveloperAnthropic's Claude Code

Our summary

Researchers at Wiz discovered a vulnerability dubbed GhostApproval affecting six popular AI-powered coding assistants. By exploiting symbolic links (symlinks), attackers can trick developers into approving edits to seemingly harmless files—while the changes actually target critical system files such as SSH keys or shell configurations. The affected tools include Amazon Q Developer, Anthropic’s Claude Code, Augment, Cursor, Google Antigravity, and Windsurf.

Three of the vendors have already issued patches, while two remain unpatched and one vendor, Anthropic, disputes the classification as a bug. The flaw allows malicious repositories to execute unauthorized actions by misleading the approval prompts shown to users. Wiz recommends updating to fixed versions and exercising caution when interacting with unfamiliar projects.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store