vulnerability
AI Coding Tools Tricked Into Hacking Developer Machine via Decades-Old Technique
High
Summary
AI coding assistants like Claude Code, Amazon Q Developer, and Cursor are vulnerable to a decades-old technique called GhostApproval, where attackers can trick the tools into accessing and modifying sensitive system files. This is achieved by planting symbolic links that mislead the AI assistant into writing to unintended locations. While some vendors have released patches, others are still working on fixes, highlighting a significant security gap in how AI tools interact with developer environments.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data