PulseAugur
EN
LIVE 18:26:51

GhostApproval vulnerability impacts 6 AI coding assistants, bypassing security checks

A newly disclosed vulnerability, dubbed GhostApproval, affects at least six AI coding assistants, potentially allowing malicious code to bypass security checks and gain system access. The flaw exploits symlink vulnerabilities to trick users into approving actions that could write to sensitive files like SSH keys. While some assistants from AWS, Cursor, and Google have been patched, others from Anthropic, Augment, and Windsurf remain vulnerable. AI

IMPACT This vulnerability could allow attackers to gain unauthorized system access through AI coding tools, highlighting the need for enhanced security in AI-powered development environments.

RANK_REASON Disclosure of a security vulnerability in AI coding assistant products.

Read on Mastodon — fosstodon.org →

AI-generated summary · Google Gemini · from 3 sources. How we write summaries →

GhostApproval vulnerability impacts 6 AI coding assistants, bypassing security checks

How we ranked this

Signal score
0 / 100
Composite score across the factors below. Higher = stronger signal that this story matters right now.
Newsworthiness bucket
Tool
Disclosure of a security vulnerability in AI coding assistant products.
Source corroboration
3 independent sources
Multiple independent publishers reporting the same story raises confidence that it's real and newsworthy.
Topics
safety, product
Editorial topic classification. Feeds into how the story surfaces on /topic/<slug> hub pages and into the per-entity coverage mix.
AI-industry relevance
High
Clearly on-topic for AI-industry coverage.
Story freshness
92 days old
Aged out of breaking-news scoring windows; ranking reflects the durable signal from the full source set.
Coverage growth since scoring
+1 source(s) since last score
New sources have picked up this story since our last re-score. Score will update on the next scoring pass.

Full methodology in our editorial standards.

COVERAGE [3]

  1. Mastodon — fosstodon.org TIER_1 Español(ES) · [email protected] ·

    Wiz discovered GhostApproval: an attack that deceives AI assistants like Claude Code, Cursor, and Amazon Q Developer using symlinks (yes, the Unix vuln from the 70s)

    Wiz descubrió GhostApproval: un ataque que engaña a asistentes de IA como Claude Code, Cursor y Amazon Q Developer usando symlinks (sí, la vuln de Unix de los 70s).El agente ve un archivo local inofensivo, pero el symlink apunta a /etc/passwd o ~/.ssh/authorized_keys. El diálogo …

  2. Mastodon — fosstodon.org TIER_1 English(EN) · [email protected] ·

    📣🚨 # GhostApproval symlink vulnerabilities in major AI coding assistants could hide sensitive file targets, bypass approval checks, and enable system access too

    📣🚨 # GhostApproval symlink vulnerabilities in major AI coding assistants could hide sensitive file targets, bypass approval checks, and enable system access too. Read: https:// hackread.com/ghostapproval-fla ws-ai-coding-tools-outside-workspace/ # CyberSecurity # AI # Vulnerabili…

  3. Mastodon — fosstodon.org TIER_1 English(EN) · [email protected] ·

    Wiz disclosed GhostApproval: a symlink flaw in 6 AI coding assistants. A malicious repo can hijack the human-in-the-loop confirmation dialog to write to ~/.ssh/

    Wiz disclosed GhostApproval: a symlink flaw in 6 AI coding assistants. A malicious repo can hijack the human-in-the-loop confirmation dialog to write to ~/.ssh/authorized_keys. AWS, Cursor, and Google patched; Anthropic, Augment, Windsurf have not. https:// go.aintelligencehub.co…