GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding Agents
ID: 46a8ac9a-bb63-581f-85bb-4a78df4f36bc
STIX ID: report--46a8ac9a-bb63-581f-85bb-4a78df4f36bc
Feed Name: The Hacker News
Researchers at Wiz disclosed "GhostApproval", a symlink-based attack against multiple AI coding assistants that causes an agent to write attacker-controlled content into sensitive files outside a project (notably SSH authorized_keys and shell startup files) by showing a deceptive approval prompt or bypassing it entirely; some vendors have fixed the issue, others have acknowledged it, and the report recommends resolving symlinks, flagging writes outside the project, and running agents with limited file access or in sandboxes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
