GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding Agents
Researchers at Wiz discovered a vulnerability dubbed GhostApproval affecting six popular AI-powered coding assistants. By exploiting symbolic links (symlinks), attackers can trick developers into approving edits to seemingly harmless files—while the changes actually target critical system files such as SSH keys or shell configurations. The affected tools include Amazon Q Developer, Anthropic’s Claude Code, Augment, Cursor, Google Antigravity, and Windsurf.
Three of the vendors have already issued patches, while two remain unpatched and one vendor, Anthropic, disputes the classification as a bug. The flaw allows malicious repositories to execute unauthorized actions by misleading the approval prompts shown to users. Wiz recommends updating to fixed versions and exercising caution when interacting with unfamiliar projects.