logo

GhostApproval Attack Impacts Amazon Q, Claude Code, Cursor, Google Antigravity, and Windsurf

ID: 60d82bf2-8932-504c-bfcd-ddffb1ad637f

STIX ID: report--60d82bf2-8932-504c-bfcd-ddffb1ad637f

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-07-09

Date Updated: 2026-07-21

Author: Divya

...
...

GhostApproval is a disclosed vulnerability affecting several AI coding assistants (including Amazon Q Developer, Claude Code, Cursor, Google Antigravity, Augment, and Windsurf) in which malicious repositories use symlinks plus misleading confirmation UI to cause tools to write attacker-controlled content to sensitive files (e.g., ~/.ssh/authorized_keys), enabling persistent remote access or RCE. The report describes PoC behavior, mixed vendor responses and CVE assignments, and recommends mitigations such as canonical path resolution, explicit out-of-workspace warnings, and pre-write authorization.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.