GhostApproval: A Trust Boundary Gap in AI Coding Assistants
ID: 6af99d3c-277c-58f5-ac6c-15601c6e711d
STIX ID: report--6af99d3c-277c-58f5-ac6c-15601c6e711d
Feed Name: Wiz Blog
This report describes “GhostApproval,” a class-level vulnerability in six major AI coding assistants where malicious repositories use symbolic links to cause agents to read or write files outside the workspace (e.g., injecting SSH keys into ~/.ssh/authorized_keys). The issue combines classic symlink-following (CWE-61) with UI misrepresentation (CWE-451) where confirmation dialogs hide the true target; some products performed pre-authorization writes, enabling immediate compromise. The authors tested Amazon Q Developer, Anthropic Claude Code, Augment, Cursor, Google Antigravity, and Windsurf, detail vendor responses (several fixes deployed, some vendors acknowledged or rejected), provide proof-of-concept attack chains, and recommend resolving symlinks before prompts, warning on out-of-workspace targets, and never writing before explicit user authorization.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
