
GhostApproval: Symlink Flaw in AI Coding Assistants Exposes Systems to Arbitrary Code Execution
AI SecurityVulnerabilitiesCode ExploitationSoftware Supply Chain
Researchers at Wiz identified a symlink flaw dubbed 'GhostApproval' in six AI coding assistants, allowing malicious code repositories to execute arbitrary commands on a developer's system. The vulnerability exploits the assistants' approval mechanism, where a seemingly harmless file edit request is redirected to a sensitive file via symlink manipulation. Affected tools include Amazon Q Developer, Anthropic's Claude Code, Augment, Cursor, Google Antigravity, and Windsurf. The attack requires user interaction but can lead to full system compromise without explicit warning. No CVE IDs, patch dates, or specific technical payloads were disclosed in the report.