GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding Agents
Researchers at Wiz discovered a vulnerability (GhostApproval) in six AI coding assistants – Amazon Q Developer, Anthropic's Claude Code, Augment, Cursor, Google Antigravity, and Windsurf – that allows malicious repositories to silently inject code into a developer's system. The flaw exploits a symlink feature, tricking the AI agent into writing to sensitive files like SSH keys and shell startup files, bypassing the approval box and presenting a false target. While Anthropic disputes the issue as a bug, the vulnerability has been independently identified by Adversa AI and has already been exploited in the wild, leading to the disabling of affected Microsoft repositories by GitHub. The broader issue highlights a growing trend of AI agents gaining excessive file access and the need for improved safeguards.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
