
GhostApproval: Symlink Flaw in AI Coding Assistants Exposes Security Risks
Security firm Wiz discovered GhostApproval, a symlink flaw affecting six major AI coding assistants, which allows attackers to bypass approval mechanisms in these tools. The vulnerability was identified in widely used AI-powered development platforms but no specific product names, CVE IDs, or affected versions were disclosed in the report. The flaw exploits improper handling of symbolic links, potentially enabling unauthorized code execution or data exfiltration. No exact timeline, patch status, or exploitation instances in the wild were mentioned. The impact includes circumvention of security controls designed to review AI-generated code before implementation. The research highlights risks in AI-assisted development workflows without further technical specifics.