GhostApproval Attack Impacts Amazon Q, Claude Code, Cursor, Google Antigravity, and Windsurf
ID: 60d82bf2-8932-504c-bfcd-ddffb1ad637f
STIX ID: report--60d82bf2-8932-504c-bfcd-ddffb1ad637f
Feed Name: GBHackers
GhostApproval is a disclosed vulnerability affecting several AI coding assistants (including Amazon Q Developer, Claude Code, Cursor, Google Antigravity, Augment, and Windsurf) in which malicious repositories use symlinks plus misleading confirmation UI to cause tools to write attacker-controlled content to sensitive files (e.g., ~/.ssh/authorized_keys), enabling persistent remote access or RCE. The report describes PoC behavior, mixed vendor responses and CVE assignments, and recommends mitigations such as canonical path resolution, explicit out-of-workspace warnings, and pre-write authorization.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
