logo

GhostApproval Flaw Hits Six Major AI Coding Assistants

ID: 4c413f84-e521-5353-af0b-ef057d4b2a53

STIX ID: report--4c413f84-e521-5353-af0b-ef057d4b2a53

Feed Name: Infosecurity Magazine (News)

Threat Score
70/100

Date Published: 2026-07-09

Date Updated: 2026-07-19

...
...

Wiz Research disclosed 'GhostApproval', a symlink-based flaw in six AI coding assistants (Amazon Q Developer, Anthropic Claude Code, Augment, Cursor, Google Antigravity, Windsurf) that can turn an approval dialog into a blind write to sensitive files — for example replacing SSH keys — enabling potential passwordless access or RCE. Wiz published a PoC, coordinated disclosure led to fixes from some vendors (Cursor issued CVE-2026-50549), while others have disputed or not patched the issue; vendors are advised to resolve symlinks before approval and flag writes outside the project.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.