news.mlab.sh
Back to the feed
threat-intel

GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding Agents

High
Image: The Hacker News
Summary

Researchers at Wiz discovered a vulnerability (GhostApproval) in six AI coding assistants – Amazon Q Developer, Anthropic's Claude Code, Augment, Cursor, Google Antigravity, and Windsurf – that allows malicious repositories to silently inject code into a developer's system. The flaw exploits a symlink feature, tricking the AI agent into writing to sensitive files like SSH keys and shell startup files, bypassing the approval box and presenting a false target. While Anthropic disputes the issue as a bug, the vulnerability has been independently identified by Adversa AI and has already been exploited in the wild, leading to the disabling of affected Microsoft repositories by GitHub. The broader issue highlights a growing trend of AI agents gaining excessive file access and the need for improved safeguards.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.