logo

GhostApproval Flaws Let Top AI Coding Tools Write Outside Workspaces

ID: 6c0a8644-23a2-59ec-aa18-9389cb0a5cbe

STIX ID: report--6c0a8644-23a2-59ec-aa18-9389cb0a5cbe

Feed Name: HackRead

Threat Score
70/100

Date Published: 2026-07-09

Date Updated: 2026-07-17

Author: Waqas

...
...

Wiz researchers disclosed “GhostApproval,” a symlink-based vulnerability in multiple AI coding assistants that can cause assistants to write attacker-controlled data to files outside a project workspace (for example ~/.ssh/authorized_keys), with some products performing writes before user approval; several vendors have issued patches or mitigations while others were pending, and researchers recommend resolving symlinks before prompting and blocking writes until explicit approval.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.