Bug in top AI coding agents shows that Unix-era security headaches never really die
ID: 12c81605-ec10-5bab-b2b3-5336a6039a8a
STIX ID: report--12c81605-ec10-5bab-b2b3-5336a6039a8a
Feed Name: The Register (Security)
Wiz disclosed a vulnerability called "GhostApproval" affecting multiple AI coding assistants in which malicious repositories use symlinks to trick agents into writing to sensitive files outside the project workspace (for example adding an attacker SSH key to ~/.ssh/authorized_keys), effectively enabling remote code execution or persistent access; several vendors patched the issue and/or issued CVEs while others acknowledged but had not patched or initially dismissed it as outside their threat model.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
