logo

GhostApproval: A Trust Boundary Gap in AI Coding Assistants

ID: 6af99d3c-277c-58f5-ac6c-15601c6e711d

STIX ID: report--6af99d3c-277c-58f5-ac6c-15601c6e711d

Feed Name: Wiz Blog

Threat Score
75/100

Date Published: 2026-07-08

Date Updated: 2026-07-23

Author: Maor Dokhanian

...
...

This report describes “GhostApproval,” a class-level vulnerability in six major AI coding assistants where malicious repositories use symbolic links to cause agents to read or write files outside the workspace (e.g., injecting SSH keys into ~/.ssh/authorized_keys). The issue combines classic symlink-following (CWE-61) with UI misrepresentation (CWE-451) where confirmation dialogs hide the true target; some products performed pre-authorization writes, enabling immediate compromise. The authors tested Amazon Q Developer, Anthropic Claude Code, Augment, Cursor, Google Antigravity, and Windsurf, detail vendor responses (several fixes deployed, some vendors acknowledged or rejected), provide proof-of-concept attack chains, and recommend resolving symlinks before prompts, warning on out-of-workspace targets, and never writing before explicit user authorization.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.