#GhostApproval
#Google owned security biz Wiz found the security gap, which it's named "GhostApproval," and reported it to all six: Amazon Q Developer, Anthropic Claude Code, Augment, Cursor, Google Antigravity, and Windsurf.

www.theregister.com/security/202...
Bug in top AI coding agents shows that Unix-era security headaches never really die
'GhostApproval' problem highlights human-in-the-loop fails
www.theregister.com
July 10, 2026 at 10:18 PM
New GhostApproval Vulnerability Affects Amazon Q, Claude Code, Cursor, and Other AI Agents
New GhostApproval Vulnerability Affects Amazon Q, Claude Code, Cursor, and Other AI Agents
A newly disclosed vulnerability pattern dubbed “GhostApproval” has exposed a critical security flaw in six of the most widely used AI coding assistants: Amazon Q Developer, Anthropic Claude Code , Augment, Cursor, Google Antigravity, and Windsurf, allowing malicious repositories to bypass Human-in-the-Loop safety controls and potentially achieve remote code execution on developer machines. Discovered by Wiz researchers, GhostApproval exploits a deceptively simple but deeply impactful technique: symbolic link following ( CWE-61 ). A symlink is a filesystem pointer that makes one path silently resolve to another. While this primitive has been exploited for decades in Docker escapes ( CVE-2024-21626 ), npm package managers ( CVE-2021-32803 ), and Linux privilege escalation, its application to AI coding agents represents a novel and systematic attack surface. The attack is elegantly simple. An attacker creates a malicious repository containing a symlink , for example, project_settings.json → ~/.ssh/authorized_keys . GhostApproval Attack (Source: Wiz) When a victim clones the repo and asks their AI coding assistant to “set up the workspace,” the agent follows the symlink and writes the attacker’s SSH public key directly to the victim’s authorized_keys file. The result: persistent, password-less SSH access to the developer’s machine. What elevates GhostApproval beyond a straightforward symlink exploit is the UI misrepresentation layer ( CWE-451 ). The most striking example was observed in Anthropic’s Claude Code. GhostApproval Anthropic’s Claude Code (Source: WIZ) During testing, the agent’s internal reasoning explicitly stated: “I can see that project_settings.json is actually a zsh configuration file.” Yet the confirmation prompt displayed to the user simply asked: “Make this edit to project_settings.json?” The agent knew the true target. The user did not. This transforms a sandbox bypass into an informed consent bypass; the Human-in-the-Loop safety net becomes a rubber stamp. Vendor Severity CVE Fixed Version Status Amazon Web Services High CVE-2026-12958 Language server v1.69.0 Fixed Google (Antigravity) Critical Pending v1.19.6 Fixed Cursor Critical CVE-2026-50549 v3.0 Fixed Augment Critical — v0.754.3 In Progress Windsurf Critical — v1.9566 (tested) In Progress Anthropic (Claude Code) Disputed — v2.1.42 Rejected / Patched Three vendors patched the vulnerability promptly: AWS, Cursor, and Google. AWS fixed the issue in language server version 1.69.0 (deployed May 27, 2026) and assigned CVE-2026-12958. The update ships automatically, and customers can trigger it by reloading their IDE. Cursor released its fix in v3.0 (June 5, 2026) under CVE-2026-50549. Google deployed its fix on May 22, 2026, and is assessing whether to issue a CVE. Augment and Windsurf acknowledged the reports but provided no further updates at the time of Wiz publication. Windsurf’s pre-authorization variant was particularly dangerous: the agent writes to disk before the Accept/Reject dialog appears, meaning the confirmation dialog functions as an undo button rather than an authorization gate. Anthropic initially rejected the report as “outside our threat model,” arguing that user-trusted directories and user-approved prompts place responsibility on the user. However, versions 2.1.173+ now resolve symlinks and warn users before writing to sensitive files. Anthropic later clarified with Wiz that this symlink warning shipped in v2.1.32 on February 5, 2026 — nine days before the report was submitted as part of proactive internal security hardening. Wiz researchers outlined three core mitigations for AI coding tool vendors: Resolve symlinks before displaying prompts — always show the canonical target path, not the symlink name Warn explicitly when the resolved path exits the workspace — a write to ~/.ssh/authorized_keys must look categorically different from a write to ./config.json Never write to disk before explicit user authorization — confirmation dialogs must be gates, not undo mechanisms Initial discovery occurred on February 10, 2026, with vendor reports submitted between February 12 and March 5, 2026. Public disclosure was made on July 8, 2026, following the 90+ day coordinated disclosure window. GhostApproval is not a collection of individual bugs; it is a category-level design gap across AI coding tools. As agents gain greater autonomy over developer filesystems, the integrity of Human-in-the-Loop controls must be treated as a first-class security requirement, not an afterthought. Stop Accepting SLAs Written for 2019 SOCs – Here’s the 2026 AI SLA Vendor Checklist – Download Free AI SOC SLA Guide The post New GhostApproval Vulnerability Affects Amazon Q, Claude Code, Cursor, and Other AI Agents appeared first on Cyber Security News .
cybersecuritynews.com
July 9, 2026 at 5:30 AM
GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding Agents #cybersecurity #hacking #news #infosec #security #technology #privacy thehackernews.com/20...
July 9, 2026 at 8:47 AM
New Podcast Episode:
Security Now: HalluSquatting, GhostApproval & GitLost
Patch Tuesday Breaks Records
with Steve Gibson, @leolaporte.me
Security Now: HalluSquatting, GhostApproval & GitLost | TWiT.TV
AI is rewriting the rules of cybersecurity, and this week, massive government and private sector moves show just how quickly the stakes are rising. Find out how regulators
twit.tv
July 15, 2026 at 3:35 AM
GhostApproval Symlink Codes Could Run Malicious Codes in AI Coding Agents #AI #aiagents #ChatGPT
GhostApproval Symlink Codes Could Run Malicious Codes in AI Coding Agents
Cyber security experts at Wiz discovered that a bug in six famous AI coding assistants allows a booby-trapped code project to silently take over a developer’s system. The assistant can ask access to edit one innocent-looking file, but the write takes over a sensitive file. The impacted tools are Windsurf, Google Antigravity, Cursor, Amazon Q Developer, Claude Code by Anthropic, and Augment. Wiz has termed the technique GhostApproval and posted it recently. Three of the six AI assistants have addressed, two did not, while Anthropic argues if it is a bug. The most vulnerable are the tools that modify file before you can notice. Attack tactic The threat actors exploit an old Unix feature called symlink (or symbolic link), that AI assistants cannot check.  A symlink silently directs to other files somewhere else on disk, hence writing to it particularly writes to the victim.  “Symbolic links have been a security headache since the early days of Unix. From /tmp race conditions to privilege escalation exploits, symlinks have a long history of bypassing security boundaries by making one path silently resolve to another. It's a well-documented attack primitive - CWE-61 dates back decades,” Wiz said. Research model Wiz made a malicious repository with a symbolic link called project_settings.json that really directs to target’s SSH login file, ~/.ssh/authorized_keys. The repo’s README commands the assistant to put “a line” to project_settings.json, and this line is the hacker’s SSH key mimicking an innocent setting. “ If you ask the agent to “set up the workspace” or “follow the README,” it writes the key directly via the symlink into the login file. Following this, if the machine plays an SSH  service the threat actor can access, they can sign in without password.  The second variant Another variant of the attack writes to your shell startup file, ~/.zshrc, which the shell runs the next moment you open a terminal without needing an SSH. There are no indications that any of this has been abused in real-time operations, Wiz has only demonstrated it as their research. “Symlinks have been exploited for decades – in race conditions (CVE-2018-15664), in package managers (CVE-2021-32803), in container escapes (CVE-2024-21626). Any time a tool writes to a user-controlled path without resolving it first, symlinks become a weapon,” Wiz wrote in its blog. 
dlvr.it
July 11, 2026 at 5:37 AM
Bug in top AI coding agents shows that Unix-era security headaches never really die
Bug in top AI coding agents shows that Unix-era security headaches never really die
'GhostApproval' problem highlights human-in-the-loop fails
www.theregister.com
July 9, 2026 at 2:01 PM
The weird new AI security problem:

If a coding model hallucinates a repo, package, or URL…

An attacker can create it.

That is HalluSquatting.

Security Now also gets into GitLost, GhostApproval, and private code leak risks.
Security Now: HalluSquatting, GhostApproval & GitLost | TWiT.TV
AI is rewriting the rules of cybersecurity, and this week, massive government and private sector moves show just how quickly the stakes are rising. Find out how regulators
buff.ly
July 16, 2026 at 7:26 PM
even writeups of security blindspots in coding agents fall into the anthropmorphism trap. Wiz says that the agent 'knew' the json file it was updating was a zsh config. a human knowing that would probably know that has implications; an agent just deriving the file purpose doesn't *know* what it is
GhostApproval: AI Coding Assistant Trust Boundary Flaw | Wiz Blog
Wiz Research uncovered GhostApproval, a trust boundary flaw affecting leading AI coding assistants that can bypass human approval and enable code execution.
www.wiz.io
July 8, 2026 at 2:21 PM
Bug in top AI coding agents shows that Unix-era security headaches never really die
Bug in top AI coding agents shows that Unix-era security headaches never really die
'GhostApproval' problem highlights human-in-the-loop fails
www.theregister.com
July 10, 2026 at 10:03 PM
Bug in top AI coding agents shows that Unix-era security headaches never really die
Bug in top AI coding agents shows that Unix-era security headaches never really die
'GhostApproval' problem highlights human-in-the-loop fails
www.theregister.com
July 8, 2026 at 2:00 PM
GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding Agents

thehackernews.com/2026/07/ghos...

#Cybersecurity #AI
GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding Agents
Wiz says GhostApproval abuses symlinks so AI coding agents write to SSH keys or shell startup files while showing benign paths.
thehackernews.com
July 9, 2026 at 4:40 AM
📣🚨 #GhostApproval symlink vulnerabilities in major AI coding assistants could hide sensitive file targets, bypass approval checks, and enable system access too.

Read: hackread.com/ghostapprova...

#CyberSecurity #AI #Vulnerability #Anthropic #ClaudeCode #Cursor
GhostApproval Flaws Let Top AI Coding Tools Write Outside Workspaces
GhostApproval symlink flaws in major AI coding assistants could hide sensitive file targets, bypass approval checks and enable system access too.
hackread.com
July 9, 2026 at 11:53 AM
AI coding assistants were tricked by GhostApproval, a symlink attack that can redirect edits outside the workspace. Wiz tested Claude Code, Amazon Q, Cursor, and others; some vendors have patched it. #GhostApproval #ClaudeCode #Wiz
AI Coding Tools Tricked Into Hacking Developer Machine via Decades-Old Technique
Wiz disclosed GhostApproval, an attack that tricks AI coding assistants into following deceptive symlinks and modifying files outside the intended workspace. The issue was tested against Claude Code, Amazon Q Developer, Cursor, Google Antigravity, Augment, and Windsurf, with some vendors already patching the flaw. #GhostApproval #ClaudeCode #AmazonQDeveloper #Cursor #GoogleAntigravity #Augment #Windsurf...
www.hendryadrian.com
July 9, 2026 at 10:15 AM
🤖 AI coding agents show vulnerability to 'GhostApproval' bug

At least six widely used AI coding assistants have a systematic vulnerability pattern that can be abused to trick agents into accessing files outside the workspace...

#GenerativeAI #DeepLearning #AIInference #AI #AIPulse
Read the full article →
www.synestesia.uk
July 8, 2026 at 5:32 PM
Six AI coding assistants share one flaw. Wiz's GhostApproval: a fake file secretly symlinked to your SSH keys, the agent writes there anyway. 3 patched, 2 exposed, 1 disputes it's a bug.

https://www.techstoriess.com/six-ai-coding-assistants-one-shared-flaw-the-vulnerability-every-enterprise-missed/
August 9, 2026 at 12:47 PM
“GhostApproval reflects several key realities of the AI era,” Dokhanian told us. “For one, human-in-the-loop isn't always the safety net it appears to be. When the confirmation prompt hides critical information, developers can't make informed decisions - the approval becomes a rubber stamp.”
Bug in top AI coding agents shows that Unix-era security headaches never really die
'GhostApproval' problem highlights human-in-the-loop fails
www.theregister.com
July 10, 2026 at 3:25 PM
🤖 GhostApproval: Wiz discovers symlink traversal in 6 AI coding assistants (Amazon Q, Claude Code, Cursor, Windsurf, Augment, Antigravity). Malicious repos can trick agents into writing to sensitive files — code execution on…
July 9, 2026 at 10:55 AM
GhostApproval is a great reminder that AI agents are just high-speed wrappers for legacy vulnerabilities. Security isn't just about the model—it’s about sandboxing your local dev environment. 🛡️ #AIsec
July 10, 2026 at 10:30 AM
-New Helix data extortion group
-Crypto-wallet extensions can link you to your crypto-funds:
-Cisco advance notification for patches next week
-GhostLock Linux vulnerability
-HalluSquatting attack
-GhostApproval attack
-GitLost attack
-RoguePlanet gets a patch
July 10, 2026 at 7:56 AM